πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ The Hard Realities of Setting AI Risk Policy πŸ•΄

Time to get real about what it takes to set and enforce cybersecurity and resilience standards for AI risk management in the enterprise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ EvilProxy Cyberattack Flood Targets Execs via Microsoft 365 πŸ•΄

A campaign sent 120,000 phishing emails in three months, circumventing MFA to compromise cloud accounts of high-level executives at global organizations

πŸ“– Read

via "Dark Reading".
πŸ”₯1
🦿 Black Hat 2023 Keynote: Navigating Generative AI in Today’s Cybersecurity Landscape 🦿

Discover the challenges that AI will bring to the cybersecurity industry and the opportunities and future implications of cybersecurity in an AI-dominated world.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Cyber Insurance Experts Make a Case for Coverage, Protection πŸ•΄

At Black Hat "mini summit," providers and customers get clearer about premium costs and coverage β€” and the risk of doing without.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Dell Credentials Bug Opens VMWare Environments to Takeover πŸ•΄

Decoding private keys from even one Dell customer could give attackers control over VMWare environments across all organizations running the same programs.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-38333 β€Ό

Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32561 β€Ό

A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32562 β€Ό

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32560 β€Ό

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution.Thanks to a Researcher at Tenable for finding and reporting.Fixed in version 6.4.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40225 β€Ό

HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.x and 2.4.x through 2.4.23, 2.5.x and 2.6.x before 2.6.15, 2.7.x before 2.7.10, and 2.8.x before 2.8.2 forwards empty Content-Length headers, violating RFC 9110 section 8.6. In uncommon cases, an HTTP/1 server behind HAProxy may interpret the payload as an extra request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37625 β€Ό

A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39806 β€Ό

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32564 β€Ό

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39805 β€Ό

iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40014 β€Ό

OpenZeppelin Contracts is a library for secure smart contract development. Starting in version 4.0.0 and prior to version 4.9.3, contracts using `ERC2771Context` along with a custom trusted forwarder may see `_msgSender` return `address(0)` in calls that originate from the forwarder with calldata shorter than 20 bytes. This combination of circumstances does not appear to be common, in particular it is not the case for `MinimalForwarder` from OpenZeppelin Contracts, or any deployed forwarder the team is aware of, given that the signer address is appended to all calls that originate from these forwarders. The problem has been patched in v4.9.3.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40224 β€Ό

MISP 2.4174 allows XSS in app/View/Events/index.ctp.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32563 β€Ό

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-28129 β€Ό

Desktop & Server Management (DSM) may have a possible execution of arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32565 β€Ό

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ CISA: 'Whirlpool' Backdoor Sends Barracuda ESG Security Down the Drain πŸ•΄

Researchers have observed China's UNC4841 dropping the backdoor on Barracuda's email security appliances, in a spiraling cyber-espionage campaign.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Rhysida Ransomware Trains Its Sights on Healthcare Operations πŸ•΄

The new group has already made an impact in multiple countries and industries, including a multistate hospital chain in the US.

πŸ“– Read

via "Dark Reading".