πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-27427 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NTZApps CRM Memberships plugin <=Γ‚ 1.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30258 β€Ό

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30362 β€Ό

Buffer Overflow vulnerability in coap_send function in libcoap library 4.3.1-103-g52cfd56 fixed in 4.3.1-120-ge242200 allows attackers to obtain sensitive information via malformed pdu.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28065 β€Ό

Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30260 β€Ό

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35048 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <=Γ‚ 1.2.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29860 β€Ό

An insecure permissions in /Taier/API/tenant/listTenant interface in DTStack Taier 1.3.0 allows attackers to view sensitive information via the getCookie method.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3302 β€Ό

Improper Neutralization of Formula Elements in a CSV File in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34012 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Premium Addons for Elementor Premium Addons PRO plugin <=Γ‚ 2.8.24 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32580 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <=Γ‚ 2.6.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3304 β€Ό

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28751 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <=Γ‚ 2.0.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-29100 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <=Γ‚ 11.6.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3303 β€Ό

Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.

πŸ“– Read

via "National Vulnerability Database".
⚠ S3 Ep140: So you think you know ransomware? ⚠

Lots to learn this week - listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
⚠ Aussie PM says, β€œShut down your phone every 24 hours for 5 mins” – but that’s not enough on its own ⚠

Don't treat rebooting your phone once a day as a cybersecurity talisman... here are 8 additional tips for better mobile phone security.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-36274 β€Ό

LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36271 β€Ό

LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Black Hat Asia 2023: Cybersecurity Maturity and Concern in Asia πŸ•΄

Black Hat Asia 2023 showed that cybersecurity is nascent among organizations in Asia with opportunities for improvement.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Microsoft Teams Attack Skips the Phish to Deliver Malware Directly πŸ•΄

Exploiting a flaw in how the app handles communication with external tenants gives threat actors an easy way to send malicious files from a trusted source to an organization's employees, but no patch is imminent.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Why Legacy System Users Prioritize Uptime Over Security πŸ•΄

For line-of-business execs, the fear of grinding mission-critical systems to a halt overrides the fear of ransomware. How can CISOs overcome this?

πŸ“– Read

via "Dark Reading".