β Thoughts on scheduled password changes (donβt call them rotations!) β
π Read
via "Naked Security".
Does swapping your password regularly make it a better password?π Read
via "Naked Security".
Naked Security
Thoughts on scheduled password changes (donβt call them rotations!)
Does swapping your password regularly make it a better password?
β More MOVEit mitigations: new patches published for further protection β
π Read
via "Naked Security".
Good news... more patches, this time available proactivelyπ Read
via "Naked Security".
Naked Security
More MOVEit mitigations: new patches published for further protection
Good news⦠more patches, this time available proactively
βΌ CVE-2023-29752 βΌ
π Read
via "National Vulnerability Database".
An issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.π Read
via "National Vulnerability Database".
βΌ CVE-2023-29755 βΌ
π Read
via "National Vulnerability Database".
An issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPreference files.π Read
via "National Vulnerability Database".
π΄ Passkeys See Fresh Momentum With New Pilot Programs π΄
π Read
via "Dark Reading".
Apple adds API that will enable sharing of passkeys across platforms, and Google offers passkey authentication in beta for Google Workspace and Google Cloud.π Read
via "Dark Reading".
Dark Reading
Passkeys See Fresh Momentum With New Pilot Programs
Apple adds API that will enable sharing of passkeys across platforms, and Google offers passkey authentication in beta for Google Workspace and Google Cloud.
βΌ CVE-2023-3188 βΌ
π Read
via "National Vulnerability Database".
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3191 βΌ
π Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3190 βΌ
π Read
via "National Vulnerability Database".
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3192 βΌ
π Read
via "National Vulnerability Database".
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25912 βΌ
π Read
via "National Vulnerability Database".
The webreport generation feature in the Danfoss AK-EM100 allows an unauthorized actor to generate a web report that discloses sensitive information such as the internal IP address, usernames and internal device values.π Read
via "National Vulnerability Database".
βΌ CVE-2023-22586 βΌ
π Read
via "National Vulnerability Database".
The Danfoss AK-EM100 web applications allow for Local File Inclusion in the file parameter.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35036 βΌ
π Read
via "National Vulnerability Database".
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.π Read
via "National Vulnerability Database".
βΌ CVE-2023-35031 βΌ
π Read
via "National Vulnerability Database".
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036.π Read
via "National Vulnerability Database".
π’ Fighting the βalways onβ culture thatβs savaging mental health in cyber security π’
π Read
via "ITPro".
With personnel already stretched due to skills shortages, workplace pressure is causing a mental health nightmare π Read
via "ITPro".
ITPro
Fighting the βalways onβ culture thatβs savaging mental health in cyber security
With personnel already stretched due to skills shortages, workplace pressure is causing a mental health nightmare
βΌ CVE-2015-10118 βΌ
π Read
via "National Vulnerability Database".
A vulnerability classified as problematic was found in cchetanonline WP-CopyProtect up to 3.0.0. This vulnerability affects the function CopyProtect_options_page of the file wp-copyprotect.php. The manipulation of the argument CopyProtect_nrc_text leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 3.1.0 is able to address this issue. The patch is identified as 8b8fe4102886b326330dc1ff06b17313fb10aee5. It is recommended to upgrade the affected component. VDB-231202 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
π’ Log4J exploits may rise further as Microsoft continues war on phishing π’
π Read
via "ITPro".
Despite Log4J patches being made almost immediately in 2021, exploit attempts are still in the tens of millions π Read
via "ITPro".
ITPro
Log4J exploits may rise further as Microsoft continues war on phishing
Despite Log4J patches being made almost immediately in 2021, exploit attempts are still in the tens of millions
π΄ Doing Less With Less: Focusing on Value π΄
π Read
via "Dark Reading".
Always reach for defense in depth with proposed security changes. Measure and test results, focus on items of greatest impact, and get C-suite members involved to drive better outcomes.π Read
via "Dark Reading".
Dark Reading
Doing Less With Less: Focusing on Value
Always reach for defense in depth with proposed security changes. Measure and test results, focus on items of greatest impact, and get C-suite members involved to drive better outcomes.
βΌ CVE-2023-33492 βΌ
π Read
via "National Vulnerability Database".
EyouCMS 1.6.2 is vulnerable to Cross Site Scripting (XSS).π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2023-33253 βΌ
π Read
via "National Vulnerability Database".
LabCollector 6.0 though 6.15 allows remote code execution. An authenticated remote low-privileged user can upload an executable PHP file and execute system commands. The vulnerability is in the message function, and is due to insufficient validation of the file (such as shell.jpg.php.shell) being sent.π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2023-34581 βΌ
π Read
via "National Vulnerability Database".
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2π Read
via "National Vulnerability Database".
βΌ CVE-2023-32961 βΌ
π Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <=Γ 7.3.3 versions.π Read
via "National Vulnerability Database".