πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-29152 β€Ό

By changing the filename parameter in the request, an attacker could delete any file with the permissions of the Vuforia server account.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-31200 β€Ό

PTC Vuforia Studio does not require a token; this could allow an attacker with local access to perform a cross-site request forgery attack or a replay attack.

πŸ“– Read

via "National Vulnerability Database".
❀2
β€Ό CVE-2023-33846 β€Ό

IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 257100.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23481 β€Ό

IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245889.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Barracuda Networks says hacked devices β€œmust be immediately replaced” despite patches πŸ“’

Seven-month exploitation of a critical vulnerability enabled persistent backdoor access in its email security gateway devices

πŸ“– Read

via "ITPro".
πŸ“’ The top malware and ransomware threats for June 2023 πŸ“’

Organizations face a fresh round of cyber threats as criminals continue to evolve their tactics

πŸ“– Read

via "ITPro".
❀1
πŸ•΄ 60K+ Android Apps Have Delivered Adware Undetected for Months πŸ•΄

A campaign targeting mainly US users disguised malware in fake security software, game cracks, cheats, free Netflix, and other "modded" apps.

πŸ“– Read

via "Dark Reading".
πŸ‘Ž1
⚠ Firefox 114 is out: No 0-days, but one fascinating β€œteachable moment” bug ⚠

With the right (or wrong, if you're on the right side of the fence) timing...

πŸ“– Read

via "Naked Security".
πŸ•΄ Easily Exploitable Microsoft Visual Studio Bug Opens Developers to Takeover πŸ•΄

The bug is very dangerous and impacts a big swath of the developer community, researchers warn.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-33660 β€Ό

A heap buffer overflow vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function copyn_str() in the file mqtt_parser.c. An attacker could exploit this vulnerability to cause a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33657 β€Ό

A use-after-free vulnerability exists in NanoMQ 0.17.2. The vulnerability can be triggered by calling the function nni_mqtt_msg_get_publish_property() in the file mqtt_msg.c. This vulnerability is caused by improper data tracing, and an attacker could exploit it to cause a denial of service attack.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Fighting AI-Powered Fraud: Let the Battle of the Machines Begin πŸ•΄

As cybercriminals tap the power of machine learning and generative AI to outwit fraud-detection systems, online fraud-prevention technologies must evolve accordingly.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Sophisticated 'Impulse Project' Crypto Scam Sprawls With 1,000 Affiliate Sites πŸ•΄

Ready-to-defraud turnkey services from Russia's Impulse Team are offered on the cyber underground and have built a campaign that has operated undetected dating back to 2016.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34570 β€Ό

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter devName at /goform/SetOnlineDevName.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34571 β€Ό

Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter shareSpeed at /goform/WifiGuestSet.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep138: I like to MOVEit, MOVEit ⚠

Backdoors, exploits, and Little Bobby Tables. Listen now! (Full transcript available...)

πŸ“– Read

via "Naked Security".
πŸ•΄ The Growing Cyber Threats of Generative AI: Who's Accountable? πŸ•΄

In the wrong hands, malicious actors can use chatbots to unleash sophisticated cyberattacks that could have devastating consequences.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-3165 β€Ό

A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-231109 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Barracuda Warns All ESG Appliances Need Urgent Rip & Replace πŸ•΄

Patching, wiping ESG devices not enough to deny threat actor access following compromise, Barracuda says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34958 β€Ό

Incorrect access control in Chamilo 1.11.* up to 1.11.18 allows a student subscribed to a given course to download documents belonging to another student if they know the document's ID.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ City of Dallas Still Clawing Back Weeks After Cyber Incident πŸ•΄

The Texas city's networks have returned to 90% functionality following the May 3 Royal ransomware attack.

πŸ“– Read

via "Dark Reading".