πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ US Patent Office Hacked, Trademark Apps Accessed πŸ•΄

Misconfiguration exposed the physical addresses of 60,000 patent filers over three years.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Cybersecurity Is the Healthcare Your Organization Needs πŸ•΄

Organizations should consider their security practices the same way people think about their well-being. Focus on staying healthy instead of finding a new pill for every security symptom you see.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep141: What was Steve Jobs’s first job? ⚠

Latest episode - listen now! (Full transcript inside.)

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-34658 β€Ό

Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26612 β€Ό

D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the HostName field in SetParentsControlInfo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36487 β€Ό

The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over the account.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37255 β€Ό

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. In Special:CheckUser, a check of the "get edits" type is vulnerable to HTML injection through the User-Agent HTTP request header.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33277 β€Ό

The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26085 β€Ό

A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37251 β€Ό

An issue was discovered in the GoogleAnalyticsMetrics extension for MediaWiki through 1.39.3. The googleanalyticstrackurl parser function does not properly escape JavaScript in the onclick handler and does not prevent use of javascript: URLs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-35830 β€Ό

STW (aka Sensor-Technik Wiedemann) TCG-4 Connectivity Module DeploymentPackage_v3.03r0-Impala and DeploymentPackage_v3.04r2-Jellyfish and TCG-4lite Connectivity Module DeploymentPackage_v3.04r2-Jellyfish allow an attacker to gain full remote access with root privileges without the need for authentication, giving an attacker arbitrary remote code execution over LTE / 4G network via SMS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26613 β€Ό

An OS command injection vulnerability in D-Link DIR-823G firmware version 1.02B05 allows unauthorized attackers to execute arbitrary operating system commands via a crafted get request to excu_shel.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36488 β€Ό

ILIAS 7.21 allows stored Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37254 β€Ό

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. XSS can occur in Special:CargoQuery via a crafted page item when using the default format.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31222 β€Ό

Deserialization of untrusted dataΓ‚ in Microsoft Messaging Queuing Service in Medtronic's Paceart Optima versions 1.11 and earlier on Windows allows an unauthorized user to impact aΓ‚ healthcare delivery organizationÒ€ℒs Paceart Optima systemΓ‚ cardiac device causing data to be deleted, stolen, or modified, or the Paceart Optima system being used for further network penetrationΓ‚ via network connectivity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26616 β€Ό

D-Link DIR-823G firmware version 1.02B05 has a buffer overflow vulnerability, which originates from the URL field in SetParentsControlInfo.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37256 β€Ό

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. It allows one to store javascript: URLs in URL fields, and automatically links these URLs.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Russian Cybersecurity Executive Arrested for Alleged Role in 2012 Megahacks β™ŸοΈ

Nikita Kislitsin, formerly the head of network security for one of Russia's top cybersecurity firms, was arrested last week in Kazakhstan in response to 10-year-old hacking charges from the U.S. Department of Justice. Experts say Kislitsin's prosecution could soon put the Kazakhstan government in a sticky diplomatic position, as the Kremlin is already signaling that it intends to block his extradition to the United States.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ AI-Enabled Voice Cloning Anchors Deepfaked Kidnapping πŸ•΄

Virtual kidnapping is just one of many new artificial intelligence attack types that threat actors have begun deploying, as voice cloning emerges as a potent new imposter tool.

πŸ“– Read

via "Dark Reading".
πŸ•΄ OTORIO Rolls Out Advanced Attack Graph Analysis for OT Security πŸ•΄

Innovative risk-based model enables better security measures.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mend.io Launches Inaugural Open Source Reliability Leaderboard πŸ•΄

New report offers valuable resource to help organizations evaluate the safety and reliability of open-source packages.

πŸ“– Read

via "Dark Reading".