πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-40343 β€Ό

Jenkins Tuleap Authentication Plugin 1.1.20 and earlier uses a non-constant time comparison function when validating an authentication token allowing attackers to use statistical methods to obtain a valid authentication token.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40338 β€Ό

Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32488 β€Ό

Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Gulf's Dizzying Tech Ambitions Present Risk & Opportunity πŸ•΄

Threats and opportunities are abound for the UAE and Gulf states, so can they deal with being a cybersecurity stronghold?

πŸ“– Read

via "Dark Reading".
πŸ›  Clam AntiVirus Toolkit 1.1.1 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software. This is the LTS source code release.

πŸ“– Read

via "Packet Storm Security".
🦿 Gartner: Generative AI Will Bring β€œTransformational Benefit” in the Next 2-5 Years 🦿

Generative AI landed on Gartner's coveted Hype Cycle for Emerging Technologies for 2023. Read about AI's transformational impact on business and society.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Mirai Common Attack Methods Remain Consistent, Effective πŸ•΄

While relatively unchanged, the notorious IoT botnet still continues to drive DDoS.

πŸ“– Read

via "Dark Reading".
⚠ β€œGrab hold and give it a wiggle” – ATM card skimming is still a thing ⚠

The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-4385 β€Ό

A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linux Kernel. This issue may allow a local attacker to crash the system due to a missing sanity check.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2737 β€Ό

Improper log permissions in SafeNet Authentication ServiceΓ‚ Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4204 β€Ό

NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could potentially facilitate firmware manipulation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39250 β€Ό

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

πŸ“– Read

via "National Vulnerability Database".
⚠ FBI warns about scams that lure you in as a mobile beta-tester ⚠

Apps on your iPhone must come from the App Store. Except when they don't... we explain what to look out for.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-4389 β€Ό

A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38737 β€Ό

IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 262567.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4387 β€Ό

A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, which could also lead to a kernel information leak problem.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Researchers Harvest, Analyze 100K Cybercrime Forum Credentials πŸ•΄

Researchers found that many Dark Web forums have stronger password rules than most government and military entities.

πŸ“– Read

via "Dark Reading".