πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-39007 β€Ό

/ui/cron/item/open in the Cron component of OPNsense before 23.7 allows XSS.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38998 β€Ό

An open redirect in the Login page of OPNsense before 23.7 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ It's Time for Cybersecurity to Talk About Climate Change πŸ•΄

From e-waste to conference swag to addressing data center energy consumption, cybersecurity stakeholders need a whole-industry approach to being part of the solution and reducing the risk of climate change.

πŸ“– Read

via "Dark Reading".
πŸ•΄ New LLM Tool Seeks and Remediates Vulnerabilities πŸ•΄

Vicarius launched vuln_GPT, which it says will generate and execute scripts to ameliorate flaws such as the TETRA backdoor.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Researchers Detail Vuln That Allowed for Windows Defender Update Process Hijack πŸ•΄

Newly patched flaw allowed attackers to sneak malware past Defender, delete benign files, and inflict mayhem on target systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Black Hat Opens With Call to Steer AI from Predictions to Policy πŸ•΄

Without cybersecurity guardrails now, AI will be harder to harness in the future.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blockchain Signing Bug Cracks Open Crypto Investors' Wallets Worldwide πŸ•΄

Bugs in popular digital signature schemes designed to protect crypto investors allow attackers to steal private keys gain full access to digital wallets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DARPA Launches Two-Year Contest to Build AI Tools to Fix Vulnerabilities πŸ•΄

A challenge will be offered to teams to build tools using AI in order to solve open source's vulnerability challenges.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-37068 β€Ό

Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33469 β€Ό

In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38348 β€Ό

A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33468 β€Ό

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23347 β€Ό

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38347 β€Ό

An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30680 β€Ό

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30704 β€Ό

Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30698 β€Ό

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

πŸ“– Read

via "National Vulnerability Database".