πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ New LLM Tool Seeks and Remediates Vulnerabilities πŸ•΄

Vicarius launched vuln_GPT, which it says will generate and execute scripts to ameliorate flaws such as the TETRA backdoor.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Researchers Detail Vuln That Allowed for Windows Defender Update Process Hijack πŸ•΄

Newly patched flaw allowed attackers to sneak malware past Defender, delete benign files, and inflict mayhem on target systems.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Black Hat Opens With Call to Steer AI from Predictions to Policy πŸ•΄

Without cybersecurity guardrails now, AI will be harder to harness in the future.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Blockchain Signing Bug Cracks Open Crypto Investors' Wallets Worldwide πŸ•΄

Bugs in popular digital signature schemes designed to protect crypto investors allow attackers to steal private keys gain full access to digital wallets.

πŸ“– Read

via "Dark Reading".
πŸ•΄ DARPA Launches Two-Year Contest to Build AI Tools to Fix Vulnerabilities πŸ•΄

A challenge will be offered to teams to build tools using AI in order to solve open source's vulnerability challenges.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-37068 β€Ό

Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL Injection attacks.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33469 β€Ό

In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38348 β€Ό

A CSRF issue was discovered in LWsystems Benno MailArchiv 2.10.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33468 β€Ό

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23347 β€Ό

HCL DRYiCE iAutomate is affected by the use of a broken cryptographic algorithm. An attacker can potentially compromise the confidentiality and integrity of sensitive information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38347 β€Ό

An issue was discovered in LWsystems Benno MailArchiv 2.10.1. Attackers can cause XSS via JavaScript content to a mailbox.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30680 β€Ό

Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30704 β€Ό

Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30698 β€Ό

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30654 β€Ό

Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30695 β€Ό

Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-30679 β€Ό

Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
❀1