πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-38812 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3180 β€Ό

A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36299 β€Ό

A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3348 β€Ό

The Wrangler command line tool (<=wrangler@3.1.0) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39097 β€Ό

WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22277 β€Ό

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-26838 β€Ό

Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition.

πŸ“– Read

via "National Vulnerability Database".
❀1
πŸ•΄ World Cup Glory Looms, and So Do Cyber Threats, Microsoft Warns πŸ•΄

The attack surface of a live event like this summer’s World Cup in Australia and New Zealand rivals that of a large multinational enterprise, or even a small city.

πŸ“– Read

via "Dark Reading".
πŸ•΄ As Artificial Intelligence Accelerates, Cybercrime Innovates πŸ•΄

Rare government, industry alignment on AI threats means we have an opportunity to make rapid strides to improve cybersecurity and slip the hold cybercriminals have on us.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Exclusive: CISA Sounds the Alarm on UEFI Security πŸ•΄

Had Microsoft had adopted a more secure update path to mitigate the BlackLotus UEFI bootkit, it might already be eliminated, a CISA official says.

πŸ“– Read

via "Dark Reading".
🦿 Cisco announces general availability of XDR platform 🦿

In alliance with Cohesity and others, Cisco is fueling near-zero latency between ransomware detection and remediation with its Extended Detection and Response platform.

πŸ“– Read

via "Tech Republic".
🦿 Arc Browser Review (2023): Pricing, Features, Alternatives and More 🦿

Learn about Arc's features, pros and cons, and what makes the web browser unique. Arc is available only for Mac and iPhone users.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Cult of the Dead Cow Hacktivists Give Life to 'Privacy-First' App Framework πŸ•΄

The well-known collective is taking on targeted advertising with the Veilid framework and says it wants to make the Internet accessible to everyone who fears being monetized.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Hactivist Group 'Mysterious Team Bangladesh' Goes on DDoS Rampage πŸ•΄

The emerging threat has carried out 750 DDoS attacks and 78 website defacements in just one year to support its religious and political motives.

πŸ“– Read

via "Dark Reading".
⚠ S3 Ep146: Tell us about that breach! (If you want to.) ⚠

Serious security stories explained clearly in plain English - listen now. (Full transcript available.)

πŸ“– Read

via "Naked Security".
🦿 Companies Should Implement ROI-Driven Cybersecurity Budgets, Expert Says 🦿

Discover the new models used to assign security budgets that succeed where traditional and outdated processes fail.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-4145 β€Ό

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/customer-data-framework prior to 3.4.2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33363 β€Ό

An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36213 β€Ό

SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33365 β€Ό

A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33366 β€Ό

A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.

πŸ“– Read

via "National Vulnerability Database".