🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
📢 NCSC expands incident response scheme to support smaller at-risk organizations 📢

Charities, small public sector organizations, and local authorities will be covered by the expanded scheme

📖 Read

via "ITPro".
📢 Proxyjacking trend continues as attackers abuse years-old GitLab vulnerability 📢

Keeping quiet and using compromised infrastructure for financial gain

📖 Read

via "ITPro".
🕴 Cyber Defenders Lead the AI Arms Race for Now 🕴

Cyber attackers are slow to implement AI in their attack chains, according to Mandiant's analysis.

📖 Read

via "Dark Reading".
CVE-2023-31074

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in hupe13 Extensions for Leaflet Map plugin <= 3.4.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-3697

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and create files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

📖 Read

via "National Vulnerability Database".
CVE-2023-2910

Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service functionality in ASUSTOR Data Master (ADM) allows remote unauthorized users to execute arbitrary commands via unspecified vectors. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

📖 Read

via "National Vulnerability Database".
CVE-2023-31091

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pradeep Singh Dynamically Register Sidebars plugin <= 1.0.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-29182

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiOS before 7.0.3 allows a privileged attacker to execute arbitrary code via specially crafted CLI commands, provided the attacker were able to evade FortiOS stack protections.

📖 Read

via "National Vulnerability Database".
CVE-2023-26530

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.

📖 Read

via "National Vulnerability Database".
CVE-2023-3698

Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.RIS1, 4.1.0 and below as well as ADM 4.2.2.RI61 and below.

📖 Read

via "National Vulnerability Database".
FBI warns about scams that lure you in as a mobile beta-tester

Apps on your iPhone must come from the App Store. Except when they don't... we explain what to look out for.

📖 Read

via "Naked Security".
👍1
📢 Ransomware profits reach "staggering" levels as businesses fail to implement MFA properly 📢

Bad multi-factor authentication practices and OneNote abuse blamed for over half of all incidents

📖 Read

via "ITPro".
🕴 How Innovation Accelerators Are at Work on the Dark Side 🕴

Digital commerce remains the richest target for cybercriminals, yet physical payment threats remain strong.

📖 Read

via "Dark Reading".
🦿 How to Retrieve and Generate Google 2FA Backup Codes 🦿

Learn how to retrieve your Google 2FA backup codes and how best to use them.

📖 Read

via "Tech Republic".
CVE-2023-38902

An issue in RG-EW series home routers and repeaters v.EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P218, RG-EG series business VPN routers v.EG_3.0(1)B11P216, EAP and RAP series wireless access points v.AP_3.0(1)B11P218, and NBC series wireless controllers v.AC_3.0(1)B11P86 allows a remote attacker to execute arbitrary code via the unifyframe-sgi.elf component in sub_40DA38.

📖 Read

via "National Vulnerability Database".
CVE-2023-38838

SQL injection vulnerability in Kidus Minimati v.1.0.0 allows a remote attacker to obtain sensitive information via the edit.php component.

📖 Read

via "National Vulnerability Database".
CVE-2023-4394

A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux Kernel. This flaw allows a local attacker with special privileges to cause a system crash or leak internal kernel information

📖 Read

via "National Vulnerability Database".
🦿 7 Ways to Access Safe Mode in Windows 10 (2023 Update) 🦿

Learn seven different ways to boot a Windows 10 PC in Safe Mode to help troubleshoot issues using this comprehensive guide.

📖 Read

via "Tech Republic".
🔥1
🕴 'Play' Ransomware Group Targeting MSPs Worldwide in New Campaign 🕴

Attackers use remote monitoring and management tools at MSPs to gain unfettered access to target networks.

📖 Read

via "Dark Reading".
S3 Ep148: Remembering crypto heroes

Celebrating the true crypto bros. Listen now (full transcript available).

📖 Read

via "Naked Security".
CVE-2023-31079

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Chris Roberts Tippy plugin <= 6.2.1 versions.

📖 Read

via "National Vulnerability Database".