πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32229 β€Ό

Due to an error in the software interface to the secure element chip on Bosch IP cameras of family CPP13 and CPP14, the chip can be permanently damaged when enabling the Stream security option (signing of the video stream) with option MD5, SHA-1 or SHA-256.

πŸ“– Read

via "National Vulnerability Database".
⚠ Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes ⚠

No zero-days this month, if you ignore the Edge RCE hole patched last week

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-3275 β€Ό

A vulnerability classified as critical was found in PHPGurukul Rail Pass Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view-pass-detail.php of the component POST Request Handler. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The identifier VDB-231625 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25450 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in GiveWP GiveWP Γ’β‚¬β€œ Donation Plugin and Fundraising Platform plugin <=Γ‚ 2.25.1 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Borderless Data vs. Data Sovereignty: Can They Co-Exist? πŸ•΄

Organizations that remain compliant with data-sovereignty regulations while enabling cross-border data sharing gain significant competitive advantage because they can make quick, agile, and informed decisions.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'Shampoo' ChromeLoader Variant Difficult to Wash Out πŸ•΄

A new version of the infamous browser extension is spreading through files on websites offering pirated wares, and leverages unique persistence mechanisms.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Angola Marks Technology Advancements With Cybersecurity Academy Plans πŸ•΄

The academy is meant to ensure a safe and strong telecommunication service and information technologies for Angola's citizens, the president said.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ CISA Order Highlights Persistent Risk at Network Edge β™ŸοΈ

The U.S. government agency in charge of improving the nation's cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes amid a surge in attacks targeting previously unknown vulnerabilities in widely used security and networking appliances.

πŸ“– Read

via "Krebs on Security".
β€Ό CVE-2023-24420 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Zestard Technologies Admin side data storage for Contact Form 7 plugin <=Γ‚ 1.1.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25055 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <=Γ‚ 2.6.1 versions.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep139: Are password rules like running through rain? ⚠

Latest episode - listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
πŸ•΄ Free Training's Role in Cybersecurity πŸ•΄

It's easy to find free training in cybersecurity, but is free the best option for entering the field?

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34666 β€Ό

Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34453 β€Ό

snappy-java is a fast compressor/decompressor for Java. Due to unchecked multiplications, an integer overflow may occur in versions prior to 1.1.10.1, causing a fatal error.The function `shuffle(int[] input)` in the file `BitShuffle.java` receives an array of integers and applies a bit shuffle on it. It does so by multiplying the length by 4 and passing it to the natively compiled shuffle function. Since the length is not tested, the multiplication by four can cause an integer overflow and become a smaller value than the true size, or even zero or negative. In the case of a negative value, a `java.lang.NegativeArraySizeException` exception will raise, which can crash the program. In a case of a value that is zero or too small, the code that afterwards references the shuffled array will assume a bigger size of the array, which might cause exceptions such as `java.lang.ArrayIndexOutOfBoundsException`.The same issue exists also when using the `shuffle` functions that receive a double, float, long and short, each using a different multiplier that may cause the same issue.Version 1.1.10.1 contains a patch for this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21141 β€Ό

In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-262244249

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21124 β€Ό

In run of multiple files, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-265798353

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29322 β€Ό

Adobe Experience Manager versions 6.5.16.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Vulcan Cyber Is a Launch Partner for Wiz Integrations (WIN) Platform πŸ•΄

Vulcan Connector for Wiz enables mutual customers to reduce cloud risk at scale.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Critical Barracuda ESG Zero-Day Linked to Novel Chinese APT πŸ•΄

A PRC-aligned actor used a trio of custom malware to take advantage of inherent weaknesses in edge appliances.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Coalition Releases Security Vulnerability Exploit Scoring System πŸ•΄

Coalition ESS uses AI to generate dynamic risk scores to help organizations mitigate their most critical risks faster.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Action1 Announces $20M Investment in Its Patch Management Platform πŸ•΄

The company aims to empower enterprises to securely manage their endpoints and remediate vulnerabilities from the cloud, enabling a work-from-anywhere environment with confidence.

πŸ“– Read

via "Dark Reading".