πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32012 β€Ό

Windows Container Manager Service Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29365 β€Ό

Windows Media Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29358 β€Ό

Windows GDI Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33139 β€Ό

Visual Studio Information Disclosure Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29361 β€Ό

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33126 β€Ό

.NET and Visual Studio Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33142 β€Ό

Microsoft SharePoint Server Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32022 β€Ό

<div data-wrapper="true" style="font-family:'Segoe UI','Helvetica Neue',sans-serif; font-size:9pt"><div>Windows Server Service Security Feature Bypass Vulnerability</div></div>

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32018 β€Ό

Windows Hello Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32009 β€Ό

Windows Collaborative Translation Framework Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32008 β€Ό

Windows Resilient File System (ReFS) Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29346 β€Ό

NTFS Elevation of Privilege Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32029 β€Ό

Microsoft Excel Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3203 β€Ό

The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_limit_product function. This makes it possible for unauthenticated attackers to update limit the number of product per category to use cache data in home screen via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3229 β€Ό

Business Logic Errors in GitHub repository fossbilling/fossbilling prior to 0.5.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47184 β€Ό

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache Traffic Server.This issue affects Apache Traffic Server: 8.0.0 to 9.2.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Dragos’ new partner program aims to turn resellers into OT experts πŸ“’

The initiative will help partners fully manage customer deployments with Dragos’ ISC/OT security offerings

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-35144 β€Ό

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35149 β€Ό

A missing permission check in Jenkins Digital.ai App Management Publisher Plugin 2.6 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL, capturing credentials stored in Jenkins.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Popular Messaging Tools Instill a False Sense of Security πŸ•΄

It's time to include messaging tool security in your cloud security program. Good first steps include tightening filter parameters on Slack and Teams.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Fixes 69 Bugs, but None Are Zero-Days πŸ•΄

The June 2023 Patch Tuesday security update included fixes for a bypass for two previously addressed issues in Microsoft Exchange and a critical elevation of privilege flaw in SharePoint Server.

πŸ“– Read

via "Dark Reading".