πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32488 β€Ό

Dell PowerScale OneFS, 8.2.x-9.5.0.x, contains an information disclosure vulnerability in NFS. A low privileged attacker could potentially exploit this vulnerability, leading to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The Gulf's Dizzying Tech Ambitions Present Risk & Opportunity πŸ•΄

Threats and opportunities are abound for the UAE and Gulf states, so can they deal with being a cybersecurity stronghold?

πŸ“– Read

via "Dark Reading".
πŸ›  Clam AntiVirus Toolkit 1.1.1 πŸ› 

Clam AntiVirus is an anti-virus toolkit for Unix. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command-line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with the Clam AntiVirus package, which you can use in your own software. This is the LTS source code release.

πŸ“– Read

via "Packet Storm Security".
🦿 Gartner: Generative AI Will Bring β€œTransformational Benefit” in the Next 2-5 Years 🦿

Generative AI landed on Gartner's coveted Hype Cycle for Emerging Technologies for 2023. Read about AI's transformational impact on business and society.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Mirai Common Attack Methods Remain Consistent, Effective πŸ•΄

While relatively unchanged, the notorious IoT botnet still continues to drive DDoS.

πŸ“– Read

via "Dark Reading".
⚠ β€œGrab hold and give it a wiggle” – ATM card skimming is still a thing ⚠

The rise of tap-to-pay and chip-and-PIN hasn't rid the world of ATM card skimming criminals...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-4385 β€Ό

A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linux Kernel. This issue may allow a local attacker to crash the system due to a missing sanity check.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-2737 β€Ό

Improper log permissions in SafeNet Authentication ServiceΓ‚ Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4204 β€Ό

NPort IAW5000A-I/O Series firmware version v2.2 and prior is affected by a hardcoded credential vulnerabilitywhich poses a potential risk to the security and integrity of the affected device. This vulnerability is attributed to the presence of a hardcoded key, which could potentially facilitate firmware manipulation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39250 β€Ό

Dell Storage Integration Tools for VMware (DSITV) 06.01.00.016 contain an information disclosure vulnerability. A local low-privileged malicious user could potentially exploit this vulnerability to retrieve an encryption key that could aid in further attacks.

πŸ“– Read

via "National Vulnerability Database".
⚠ FBI warns about scams that lure you in as a mobile beta-tester ⚠

Apps on your iPhone must come from the App Store. Except when they don't... we explain what to look out for.

πŸ“– Read

via "Naked Security".
β€Ό CVE-2023-4389 β€Ό

A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38737 β€Ό

IBM WebSphere Application Server Liberty 22.0.0.13 through 23.0.0.7 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. IBM X-Force ID: 262567.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4387 β€Ό

A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleaning up vmxnet3_rq_cleanup_all, which could also lead to a kernel information leak problem.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Researchers Harvest, Analyze 100K Cybercrime Forum Credentials πŸ•΄

Researchers found that many Dark Web forums have stronger password rules than most government and military entities.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20209 β€Ό

A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could result in remote code execution on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to establish a remote shell with root privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4383 β€Ό

A vulnerability, which was classified as critical, was found in MicroWorld eScan Anti-Virus 7.0.32 on Linux. This affects an unknown part of the file runasroot. The manipulation leads to incorrect execution-assigned permissions. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-237315. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

πŸ“– Read

via "National Vulnerability Database".