πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ“’ β€˜Borderline irresponsible’ attitude to third party risks must change, says expert πŸ“’

Firms that don’t interrogate their supply chains could face the consequences

πŸ“– Read

via "ITPro".
πŸ•΄ Millions of Repos on GitHub Are Potentially Vulnerable to Hijacking πŸ•΄

Many organizations are unwittingly exposing users of their code repositories to repojacking when renaming projects, a new study shows.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Deception Technologies Have a Maturity Problem πŸ•΄

While there's plenty of upside to rolling out deception technologies, it's not clear if cybersecurity leaders β€” or their organizations β€” are ready for them.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Government Contractors & Agencies Should Navigate New Cyber Rules πŸ•΄

The impending regulations highlight the increasing importance of enhanced network security and regulatory compliance across the government sector.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34021 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <=Γ‚ 3.7.29 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27427 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <=Γ‚ 1.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30258 β€Ό

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30362 β€Ό

Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28065 β€Ό

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30260 β€Ό

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35048 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29860 β€Ό

An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3302 β€Ό

Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34012 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <=Γ‚ 2.8.24 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32580 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <=Γ‚ 2.6.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3304 β€Ό

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28751 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <=Γ‚ 2.0.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29100 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <=Γ‚ 11.6.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3303 β€Ό

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep140: So you think you know ransomware? ⚠

Lots to learn this week - listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
⚠ Aussie PM says, β€œShut down your phone every 24 hours for 5 mins” – but that’s not enough on its own ⚠

Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

πŸ“– Read

via "Naked Security".