πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-24032 β€Ό

In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instance) can execute commands as root by passing one of JVM arguments, leading to local privilege escalation (LPE).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33243 β€Ό

RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect users' passwords in case of a database compromise, this is rendered ineffective when allowing to authenticate using the password hash.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Do I Protect My API Keys From Appearing in GitHub Search Results? πŸ•΄

A few lines of code can help you prevent accidental exposure, manage sensitive information, and maintain different configurations for various environments.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-28810 β€Ό

Some access control/intercom products have unauthorized modification of device network configuration vulnerabilities. Attackers can modify device network configuration by sending specific data packets to the vulnerable interface within the same local network.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2080 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-32025 β€Ό

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29349 β€Ό

Microsoft ODBC and OLE DB Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32027 β€Ό

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34845 β€Ό

Bludit v3.14.1 was discovered to contain an arbitrary file upload vulnerability in the component /admin/new-content. This vulnerability allows attackers to execute arbitrary web scripts or HTML via uploading a crafted SVG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32026 β€Ό

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3291 β€Ό

Heap-based Buffer Overflow in GitHub repository gpac/gpac prior to 2.2.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2788 β€Ό

Mattermost fails to check if an admin user account active after an oauth2 flow is started, allowing an attacker with admin privileges to retain persistent access to Mattermost by obtaining an oauth2 access token while the attacker's account is deactivated.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34154 β€Ό

Vulnerability of undefined permissions in HUAWEI VR screen projection.Successful exploitation of this vulnerability will cause third-party apps to create windows in an arbitrary way, consuming system resources.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2786 β€Ό

Mattermost fails to properly check theΓ‚ permissions when executing commands allowing a member with no permissionsΓ‚ to post a message in a channel to actually post it by executing channel commands.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Latest arrest places LockBit firmly in the crosshairs of international cyber police πŸ“’

The threat group could be set for a fate reminiscent of REvil

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-2785 β€Ό

Mattermost fails to properly truncate the postgres error log message of a search query failure allowing an attacker to cause the creation ofΓ‚ large log files

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2793 β€Ό

Mattermost fails to validate links on external websites when constructing a preview for a linked website, allowing an attacker to cause a denial-of-service by a linking to a specially crafted webpage in a message.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
πŸ•΄ HashiCorp Expands PAM, Secrets Management Capabilities πŸ•΄

The new privileged access management and secrets management capabilities tackles access issues and secret sprawl across the cloud environment.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybercrime Doesn't Take a Vacation πŸ•΄

Organizations need to prepare for security threats as summer holidays approach.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-26537 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nicolly WP No External Links plugin <=Γ‚ 1.0.2 versions.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-26527 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <=Γ‚ 1.4 versions.

πŸ“– Read

via "National Vulnerability Database".
❀2