🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-39507

Improper authorization in the custom URL scheme handler in "Rikunabi NEXT" App for Android prior to ver. 11.5.0 allows a malicious intent to lead the vulnerable App to access an arbitrary website.

📖 Read

via "National Vulnerability Database".
CVE-2023-4374

The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs.

📖 Read

via "National Vulnerability Database".
1
CVE-2023-3958

The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. This was partially patched in version 1.2.12 and fully patched in version 1.2.13.

📖 Read

via "National Vulnerability Database".
1
📢 Business email compromise attack costs far exceeding ransomware losses 📢

The increasingly popular phishing attack method is enabling threat actors to reap serious financial rewards

📖 Read

via "ITPro".
CVE-2023-30473

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-30784

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Kaya Studio Kaya QR Code Generator plugin <= 1.5.2 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-30782

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Andy Moyle Church Admin plugin <= 3.7.5 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-30871

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PT Woo Plugins (by Webdados) Stock Exporter for WooCommerce plugin <= 1.1.0 versions.

📖 Read

via "National Vulnerability Database".
🕴 Mandiant Releases Scanner to Identify Compromised NetScaler ADC, Gateways 🕴

Mandiant's IoC Scanner will help enterprises collect indicators of compromise on affected Citrix NetScaler products.

📖 Read

via "Dark Reading".
CVE-2023-30779

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jonathan Daggerhart Query Wrangler plugin <= 1.5.51 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-30785

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Video Grid plugin <= 1.21 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-4241

lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.

📖 Read

via "National Vulnerability Database".
CVE-2023-30786

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Benjamin Guy Captcha Them All plugin <= 1.3.3 versions.

📖 Read

via "National Vulnerability Database".
🕴 QR Code Phishing Campaign Targets Top US Energy Company 🕴

Attackers sent more than 1,000 emails with 2FA, MFA, and other security-related lures aimed at stealing Microsoft credentials.

📖 Read

via "Dark Reading".
🕴 Iran and the Rise of Cyber-Enabled Influence Operations 🕴

Iranian threat actors are combining offensive network ops with messaging and amplification to manipulate targets' perceptions and behavior. Here are three examples.

📖 Read

via "Dark Reading".
🕴 Boards Don't Want Security Promises — They Want Action 🕴

CISOs must demonstrate that security processes and updates reduce risk in measurable ways. Put emphasis on action, get the basics right, and improve processes.

📖 Read

via "Dark Reading".
CVE-2023-32494

Dell PowerScale OneFS, 8.0.x-9.5.x, contains an improper handling of insufficient privileges vulnerability. A local privileged attacker could potentially exploit this vulnerability, leading to elevation of privilege and affect in compliance mode also.

📖 Read

via "National Vulnerability Database".
CVE-2022-4782

The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

📖 Read

via "National Vulnerability Database".
CVE-2023-2271

The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack

📖 Read

via "National Vulnerability Database".
CVE-2023-1977

The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.

📖 Read

via "National Vulnerability Database".
CVE-2023-4381

Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.

📖 Read

via "National Vulnerability Database".