πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 3 Major Email Security Standards Falling Down on the Job πŸ•΄

Nearly 90% of malicious emails manage to get past SPF, DKIM, or DMARC, since threat actors are apparently using the same filters as legitimate users.

πŸ“– Read

via "Dark Reading".
❀1
β€Ό CVE-2023-39848 β€Ό

DVWA v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at blind\source\high.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39843 β€Ό

Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38866 β€Ό

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39841 β€Ό

Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39842 β€Ό

Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38864 β€Ό

An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39852 β€Ό

Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39851 β€Ό

webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39849 β€Ό

Pikachu v1.0 was discovered to contain a SQL injection vulnerability via the $username parameter at \inc\function.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20560 β€Ό

Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD RyzenΓ’β€žΒ’ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39850 β€Ό

Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20564 β€Ό

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD RyzenΓ’β€žΒ’ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.

πŸ“– Read

via "National Vulnerability Database".
🦿 Get Norton 360 Standard on 2 Devices Plus Identity Theft Protection for $24.99 🦿

This exclusive bundle includes online dark web monitoring and identity theft support, so don't miss out on this discounted year-long subscription.

πŸ“– Read

via "Tech Republic".
πŸ“’ How MSSPs can leverage dark web intelligence to counter emerging threats πŸ“’

Dark web intelligence can be a vital tool for MSSPs to bolster security and counter emerging threats

πŸ“– Read

via "ITPro".
❀1
β€Ό CVE-2023-26140 β€Ό

Versions of the package @excalidraw/excalidraw from 0.0.0 are vulnerable to Cross-site Scripting (XSS) via embedded links in whiteboard objects due to improper input sanitization.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39507 β€Ό

Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4374 β€Ό

The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs.

πŸ“– Read

via "National Vulnerability Database".
❀1
β€Ό CVE-2023-3958 β€Ό

The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This was partially patched in version 1.2.12 and fully patched in version 1.2.13.

πŸ“– Read

via "National Vulnerability Database".
❀1
πŸ“’ Business email compromise attack costs far exceeding ransomware losses πŸ“’

The increasingly popular phishing attack method is enabling threat actors to reap serious financial rewards

πŸ“– Read

via "ITPro".