πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-29708 β€Ό

An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows attackers to force a factory reset via crafted payload.

πŸ“– Read

via "National Vulnerability Database".
❀1
πŸ•΄ 2 More Apple Zero-Days Exploited in Ongoing iOS Spy Campaign πŸ•΄

The zero-day security bugs are being used to deploy the sophisticated but "odd" TriangleDB spying implant on targeted iOS devices.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Lessons From a Pen Tester: 3 Steps to Stay Safer πŸ•΄

From hardening Windows systems to adding access control and segmenting the network, there are steps organizations can take to better secure corporate data.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-27452 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator Γ’β‚¬β€œ easily Button Builder plugin <=Γ‚ 2.3.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35093 β€Ό

Broken Access Control vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin Γ’β‚¬β€œ for Online Courses and Education plugin <=Γ‚ 3.0.8 versions allowsΓ‚ any logged-in users, such as subscribers to view the "Orders" of the plugin and get the data related to the order likeΓ‚ email, username, and more.

πŸ“– Read

via "National Vulnerability Database".
❀1
πŸ•΄ IT Staff Increasingly Saddled With Data Protection Compliance πŸ•΄

Compliance, seen as a burden for businesses, is being passed to overloaded IT departments β€” leaving organizations unsure if they're compliant at all.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 6 Attack Surfaces You Must Protect πŸ•΄

More connectivity means more potential ways into your enterprise, so securing every main attack surface is imperative.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Patch Now: Cisco AnyConnect Bug Exploit Released in the Wild πŸ•΄

A ready-made, low-complexity path to pwning the popular enterprise VPN clients for remote workers is now circulating in the wild.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-36362 β€Ό

An issue in the rel_sequences component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36370 β€Ό

An issue in the gc_col component of MonetDB Server v11.45.17 and v11.46.0 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep140: So you think you know ransomware? ⚠

Lots to learn this week - listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
πŸ•΄ 5 Steps for Minimizing Dark Data Risk πŸ•΄

Dark data may be your most elusive asset, but it can also be your most costly if you don't protect it.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2611 β€Ό

Advantech R-SeeNet versions 2.4.22 is installed with a hidden root-level user that is not available in the users list. This hidden user has a password that cannot be changed by users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3256 β€Ό

Advantech R-SeeNet versions 2.4.22 allows low-level users to access and load the content of local files.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Azure AD 'Log in With Microsoft' Authentication Bypass Affects Thousands πŸ•΄

The "nOAuth" attack allows cross-platform spoofing and full account takeovers, and enterprises need to remediate the issue immediately, researchers warn.

πŸ“– Read

via "Dark Reading".
β™ŸοΈ SMS Phishers Harvested Phone Numbers, Shipment Data from UPS Tracking Tool β™ŸοΈ

The United Parcel Service (UPS) says fraudsters have been harvesting phone numbers and other information from its online shipment tracking tool in Canada to send highly targeted SMS phishing (a.k.a. "smishing") messages that spoofed UPS and other top brands. The missives addressed recipients by name, included details about recent orders, and warned that those orders wouldn't be shipped unless the customer paid an added delivery fee.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ Even With No Recession, Smaller Firms Aim to Consolidate Security Tools πŸ•΄

Small and midsized companies work to jettison some security tools to simplify operations and reduce cost, even as any economic downturn continues to remain at bay.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Tanium Platform Advances Threat Identification Capabilities and Enhances Endpoint Reach πŸ•΄

Award-winning XEM platform introduces advanced SBOM capabilities, expanded ARM support, and additional Risk & Compliance improvements.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-36243 β€Ό

FLVMeta v1.2.1 was discovered to contain a buffer overflow via the xml_on_metadata_tag_only function at dump_xml.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34923 β€Ό

XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad actors with credentials to authenticate with the Identity Provider (IP) to impersonate any TOPdesk user via SAML Response manipulation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Former Duo Security Co-Founder Jon Oberheide Joins DNSFilter Board of Directors πŸ•΄

Cybersecurity expert and proven entrepreneur to help protective DNS leader drive vision and scale through hypergrowth.

πŸ“– Read

via "Dark Reading".