πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-28031 β€Ό

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3381 β€Ό

A vulnerability classified as problematic was found in SourceCodester Online School Fees System 1.0. Affected by this vulnerability is an unknown functionality of the file /paysystem/datatable.php of the component GET Parameter Handler. The manipulation of the argument doj leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-232237 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28034 β€Ό

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potentially exploit this vulnerability in order to modify a UEFI variable.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ EU regulators are digging their heels in despite big tech’s Data Act pushback πŸ“’

EU regulators are no strangers to big tech regulatory push back, so why do companies still persist?

πŸ“– Read

via "ITPro".
πŸ“’ β€˜Borderline irresponsible’ attitude to third party risks must change, says expert πŸ“’

Firms that don’t interrogate their supply chains could face the consequences

πŸ“– Read

via "ITPro".
πŸ•΄ Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking πŸ•΄

Many organizations are unwittingly exposing users of their code repositories to repojacking when renaming projects, a new study shows.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Deception Technologies Have a Maturity Problem πŸ•΄

While there's plenty of upside to rolling out deception technologies, it's not clear if cybersecurity leaders β€” or their organizations β€” are ready for them.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Government Contractors & Agencies Should Navigate New Cyber Rules πŸ•΄

The impending regulations highlight the increasing importance of enhanced network security and regulatory compliance across the government sector.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34021 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <=Γ‚ 3.7.29 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27427 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <=Γ‚ 1.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30258 β€Ό

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30362 β€Ό

Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28065 β€Ό

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30260 β€Ό

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35048 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29860 β€Ό

An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3302 β€Ό

Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34012 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <=Γ‚ 2.8.24 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32580 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <=Γ‚ 2.6.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3304 β€Ό

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28751 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <=Γ‚ 2.0.3 versions.

πŸ“– Read

via "National Vulnerability Database".