๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด Top Takeaways From Table Talks With Fortune 100 CISOs ๐Ÿ•ด

As organizations struggle to keep up with new regulations and hiring challenges, chief information security officers share common challenges and experiences.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-1672 โ€ผ

A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35780 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Andy Whalen Galleria plugin <=ร‚ 1.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24417 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in tiggersWelt.Net Worthy plugin <=ร‚ 1.6.5-6497609 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-3269 โ€ผ

A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root privileges.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25706 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Pagup WordPress Robots.Txt optimization plugin <=ร‚ 1.4.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34029 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <=ร‚ 2.3.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36522 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in WePupil Quiz Expert plugin <=ร‚ 1.5.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34185 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <=ร‚ 0.5.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35047 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <=ร‚ 1.3.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-34561 โ€ผ

A buffer overflow in the level parsing code of RobTop Games AB Geometry Dash v2.113 allows attackers to execute arbitrary code via entering a Geometry Dash level.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35773 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Danny Hearnah - ChubbyNinjaa Template Debugger plugin <=ร‚ 3.1.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-25443 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Button Generator รขโ‚ฌโ€œ easily Button Builder plugin <=ร‚ 2.3.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35778 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <=ร‚ 1.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32104 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Mark Tilly MyCurator Content Curation plugin <=ร‚ 3.74 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35044 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Drew Phillips Securimage-WP plugin <=ร‚ 3.6.16 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35091 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in StoreApps Stock Manager for WooCommerce plugin <=ร‚ 2.10.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-23671 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Layer Slider plugin <=ร‚ 1.1.9.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โ€ผ CVE-2023-36690 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in VibeThemes WPLMS theme <=ร‚ 4.900 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1
โš  Apple silently pulls its latest zero-day update โ€“ what now? โš 

Previously, we said "do it today", but now we're forced back on: "Do not delay; do it as soon as Apple and your device will let you."

๐Ÿ“– Read

via "Naked Security".
โค1
โ€ผ CVE-2023-3620 โ€ผ

Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.

๐Ÿ“– Read

via "National Vulnerability Database".
โค1