πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-3423 β€Ό

Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Preventing Cyberattacks on Schools Starts With K–12 Cybersecurity Education πŸ•΄

By investing in a strong future cybersecurity workforce, we can prevent future attacks on US critical infrastructure before they occur.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34395 β€Ό

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider.In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver parameters that allow the loading of arbitrary dynamic-link libraries, resulting in command execution.Starting version 4.0.0 driver can be set only from the hook constructor.This issue affects Apache Airflow ODBC Provider: before 4.0.0.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35798 β€Ό

Input Validation vulnerability in Apache Software Foundation Apache Airflow ODBC Provider, Apache Software Foundation Apache Airflow MSSQL Provider.ThisΓ‚ vulnerability is considered low since it requires DAG code to use `get_sqlalchemy_connection` and someone with access to connection resources specificallyΓ‚ updating the connection to exploit it.This issue affects Apache Airflow ODBC Provider: before 4.0.0; Apache Airflow MSSQL Provider: before 3.4.1.It is recommended toΓ‚ upgrade to a version that is not affected

πŸ“– Read

via "National Vulnerability Database".
❀1
πŸ›  Proxmark3 4.16717 Custom Firmware πŸ› 

This is a custom firmware written for the Proxmark3 device. It extends the currently available firmware.

πŸ“– Read

via "Packet Storm Security".
β€Ό CVE-2023-0873 β€Ό

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1166 β€Ό

The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2627 β€Ό

The KiviCare WordPress plugin before 3.2.1 does not have proper CSRF and authorisation checks in various AJAX actions, allowing any authenticated users, such as subscriber to call them. Attacks include but are not limited to: Add arbitrary Clinic Admin/Doctors/etc and update plugin's settings

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Zscaler plots a course for zero trust leader ahead of Zenith Live conference πŸ“’

Zscaler will be hoping to capitalise on recent successes by giving a strong showing at the company's annual cyber security conference in Berlin

πŸ“– Read

via "ITPro".
⚠ UK hacker busted in Spain gets 5 years over Twitter hack and more ⚠

Not just that infamous Twitter hack, but SIM-swapping, stalking and swatting too...

πŸ“– Read

via "Naked Security".
πŸ“’ Kaseya acknowledges partner program β€˜teething problems’, promises to hire more account managers πŸ“’

Partners have complained of an inconsistent account service since Kaseya bought Datto last year

πŸ“– Read

via "ITPro".
πŸ•΄ Why the FDA's SBOM Mandate Changes the Game for OSS Security πŸ•΄

The new FDA software bill of materials (SBOM) guidelines for medical devices could have broad impact on the healthcare industry and the broader open source ecosystem.

πŸ“– Read

via "Dark Reading".
πŸ‘1πŸ‘1
πŸ•΄ Why Cyber Funding Flows for Rural Water Systems πŸ•΄

The $7.5 million in new funds from the Cybersecurity for Rural Water Systems Act of 2023 is not just a drop in the bucket for crucially important rural water systems.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34830 β€Ό

i-doit Open v24 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the timeout parameter on the login page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35800 β€Ό

Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.

πŸ“– Read

via "National Vulnerability Database".
🀯1
πŸ•΄ Pilot Applicant Information for American, Southwest Hacked πŸ•΄

The attack exposed personal information from pilot applicants, prompting both airlines to ditch their third-party provider and move services internally.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Most Enterprise SIEMs Blind to MITRE ATT&CK Tactics πŸ•΄

Organizations are largely deluded about their own security postures, according to an analysis, with the average SIEM failing to detect a whopping 76% of attacker TTPs.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-29068 β€Ό

A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34835 β€Ό

A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ U.K. Cyber Thug β€œPlugwalkJoe” Gets 5 Years in Prison β™ŸοΈ

Joseph James "PlugwalkJoe" O'Connor, a 24-year-old from the United Kingdom who earned his 15 minutes of fame by participating in the July 2020 hack of Twitter, has been sentenced to five years in a U.S. prison. That may seem like harsh punishment for a brief and very public cyber joy ride. But O'Connor also pleaded guilty in a separate investigation involving a years-long spree of cyberstalking and cryptocurrency theft enabled by "SIM swapping," a crime wherein fraudsters trick a mobile provider into diverting a customer's phone calls and text messages to a device they control.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ UCLA, Siemens Among Latest Victims of Relentless MOVEit Attacks πŸ•΄

Cl0p ransomware group uses its Dark Web leak site to identify five new victims of MOVEit cyberattacks.

πŸ“– Read

via "Dark Reading".