πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-33496 β€Ό

xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31116 β€Ό

An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29168 β€Ό

The local Vuforia web application does not support HTTPS, and federated credentials are passed via basic authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29502 β€Ό

Before importing a project into Vuforia, a user could modify the Ò€œresourceDirectoryҀ� attribute in the appConfig.json file to be a different path.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2904 β€Ό

The External Visitor Manager portal of HIDÒ€ℒs SAFE versions 5.8.0 through 5.11.3 are vulnerable to manipulation within web fields in the application programmable interface (API). An attacker could log in using account credentials available through a request generated by an internal user and then manipulate the visitor-id within the web API to access the personal data of other users. There is no limit on the number of requests that can be made to the HID SAFE Web Server, so an attacker could also exploit this vulnerability to create a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29152 β€Ό

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-31200 β€Ό

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

πŸ“– Read

via "National Vulnerability Database".
❀2
β€Ό CVE-2023-33846 β€Ό

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 257100.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23481 β€Ό

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Barracuda Networks says hacked devices β€œmust be immediately replaced” despite patches πŸ“’

Seven-month exploitation of a critical vulnerability enabled persistent backdoor access in its email security gateway devices

πŸ“– Read

via "ITPro".
πŸ“’ The top malware and ransomware threats for June 2023 πŸ“’

Organizations face a fresh round of cyber threats as criminals continue to evolve their tactics

πŸ“– Read

via "ITPro".
❀1
πŸ•΄ 60K+ Android Apps Have Delivered Adware Undetected for Months πŸ•΄

A campaign targeting mainly US users disguised malware in fake security software, game cracks, cheats, free Netflix, and other "modded" apps.

πŸ“– Read

via "Dark Reading".
πŸ‘Ž1
⚠ Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug ⚠

With the right (or wrong, if you're on the right side of the fence) timing...

πŸ“– Read

via "Naked Security".
πŸ•΄ Easily Exploitable Microsoft Visual Studio Bug Opens Developers to Takeover πŸ•΄

The bug is very dangerous and impacts a big swath of the developer community, researchers warn.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33660 β€Ό

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33657 β€Ό

A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fighting AI-Powered Fraud: Let the Battle of the Machines Begin πŸ•΄

As cybercriminals tap the power of machine learning and generative AI to outwit fraud-detection systems, online fraud-prevention technologies must evolve accordingly.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Sophisticated 'Impulse Project' Crypto Scam Sprawls With 1,000 Affiliate Sites πŸ•΄

Ready-to-defraud turnkey services from Russia's Impulse Team are offered on the cyber underground and have built a campaign that has operated undetected dating back to 2016.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34570 β€Ό

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34571 β€Ό

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep138: I like to MOVEit, MOVEit ⚠

Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)

πŸ“– Read

via "Naked Security".