โผ CVE-2023-33951 โผ
๐ Read
via "National Vulnerability Database".
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.๐ Read
via "National Vulnerability Database".
โค1
๐ฆฟ Hardware-bound passkeys are still ultimate in security: Yubico VP ๐ฆฟ
๐ Read
via "Tech Republic".
Derek Hanson, Yubicoโs VP of standards and alliances and an industry expert on passkeys, discusses why device-bound-to-shareable passkeys are critical.๐ Read
via "Tech Republic".
TechRepublic
Hardware-bound passkeys are still ultimate in security: Yubico VP
Derek Hanson, Yubicoโs VP of standards and alliances and an industry expert on passkeys, discusses why device-bound-to-shareable passkeys are critical.
โผ CVE-2023-3321 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially craftedprograms to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.This issue affects ABB Abilityรขโยข zenon: from 11 build through 11 build 106404.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3324 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially craftedprograms to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.This issue affects ABB Abilityรขโยข zenon: from 11 build through 11 build 106404.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26077 โผ
๐ Read
via "National Vulnerability Database".
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3323 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially craftedprograms to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.This issue affects ABB Abilityรขโยข zenon: from 11 build through 11 build 106404.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3322 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially craftedprograms to exploit the vulnerabilities by allowing them to run on the zenon installed hosts.This issue affects ABB Abilityรขโยข zenon: from 11 build through 11 build 106404.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-34478 โผ
๐ Read
via "National Vulnerability Database".
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.Mitigation:ร Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+๐ Read
via "National Vulnerability Database".
โผ CVE-2023-37613 โผ
๐ Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the asset src parameter.๐ Read
via "National Vulnerability Database".
๐ฆฟ How to Easily Block IP Addresses From Accessing a Desktop or Server ๐ฆฟ
๐ Read
via "Tech Republic".
In this How to Make Tech Work tutorial, Jack Wallen shows how to add another layer of security to your Linux machines with just two files.๐ Read
via "Tech Republic".
TechRepublic
How to Easily Block IP Addresses From Accessing a Desktop or Server
In this How to Make Tech Work tutorial, Jack Wallen shows how to add another layer of security to your Linux machines with just two files.
๐ฆฟ Independent Ada Lovelace Institute Asks UK Government to Firm up AI Regulation Proposals ๐ฆฟ
๐ Read
via "Tech Republic".
While the United Nations hashes out regulations, the UKโs โcontext-basedโ approach is intended to spur innovation but may cause uncertainty in the industry.๐ Read
via "Tech Republic".
TechRepublic
Independent Ada Lovelace Institute Asks UK Government to Firm up AI Regulation Proposals
While the United Nations hashes out regulations, the UKโs โcontext-basedโ approach is intended to spur innovation but may cause uncertainty in the industry.
๐ฆฟ How to Easily Block IP Addresses From Accessing a Desktop or Server ๐ฆฟ
๐ Read
via "Tech Republic".
In this How to Make Tech Work tutorial, Jack Wallen shows how to add another layer of security to your Linux machines with just two files.๐ Read
via "Tech Republic".
TechRepublic
How to Block IP Addresses From Accessing a Desktop or Server in Linux
In this How to Make Tech Work tutorial, Jack Wallen shows how to add another layer of security to your Linux machines with just two files.
โผ CVE-2021-39421 โผ
๐ Read
via "National Vulnerability Database".
A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-20593 โผ
๐ Read
via "National Vulnerability Database".
An issue in รขโฌลZen 2รขโฌ๏ฟฝ CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.๐ Read
via "National Vulnerability Database".
๐ฆฟ OpenAI, Google and More Agree to White House List of Eight AI Safety Assurances ๐ฆฟ
๐ Read
via "Tech Republic".
Assurances include watermarking, reporting about capabilities and risks, investing in safeguards to prevent bias and more. ๐ Read
via "Tech Republic".
TechRepublic
IBM, Salesforce Pledge to White House List of Eight AI Safety Assurances
Assurances include watermarking, reporting about capabilities and risks and investing in safeguards to prevent bias.
โ Apple ships that recent โRapid Responseโ spyware patch to everyone, fixes a second zero-day โ
๐ Read
via "Naked Security".
Another month, another patch for in-the-wild iPhone malware (and a whole lot more).๐ Read
via "Naked Security".
Sophos News
Naked Security โ Sophos News
โผ CVE-2023-22428 โผ
๐ Read
via "National Vulnerability Database".
Improper privilege validation in Command Centre Server allows authenticated operators to modify Division lineage.This issue affects Command Centre: vEL8.80 prior to vEL8.80.1192 (MR2), vEL8.70 prior to vEL8.70.2185 (MR4), vEL8.60 prior to vEL8.60.2347 (MR6), vEL8.50 prior to vEL8.50.2831(MR8), vEL8.40 and prior.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3871 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Campcodes Beauty Salon Management System 1.0. This affects an unknown part of the file /admin/edit_category.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235233 was assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-26045 โผ
๐ Read
via "National Vulnerability Database".
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk. This issue is patched in version 2.8.7. As a workaround, site maintainers can cherry pick the fix into their codebase to patch the exploit.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-3879 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability was found in Campcodes Beauty Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/del_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235241 was assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-33777 โผ
๐ Read
via "National Vulnerability Database".
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.๐ Read
via "National Vulnerability Database".