๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-4212 โ€ผ

?A command injection vulnerability exists in Trane XL824, XL850, XL1050, and Pivot thermostats allowing an attacker to execute arbitrary commands as root using a specially crafted filename. The vulnerability requires physical access to the device via a USB stick.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-36648 โ€ผ

The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the host via execute a malformed program in the guest OS.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-48538 โ€ผ

In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of improper validation in the PHP code: cacti_ldap_auth() allows a zero as the password.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-37434 โ€ผ

Multiple vulnerabilities in the web-based managementร‚ interface of EdgeConnect SD-WAN Orchestrator could allowร‚ an authenticated remote attacker to conduct SQL injectionร‚ attacks against the EdgeConnect SD-WAN Orchestratorร‚ instance. An attacker could exploit these vulnerabilities toร‚  ร‚  obtain and modify sensitive information in the underlyingร‚ database potentially leading to the exposure and corruptionร‚ of sensitive data controlled by the EdgeConnect SD-WANร‚ Orchestrator host.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-20813 โ€ผ

Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-38666 โ€ผ

Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in mp4encrypt.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39599 โ€ผ

Cross-Site Scripting (XSS) vulnerability in CSZ CMS v.1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Social Settings parameter.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-45611 โ€ผ

An issue was discovered in Fresenius Kabi PharmaHelp 5.1.759.0 allows attackers to gain escalated privileges via via capture of user login information.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-21687 โ€ผ

Buffer Overflow vulnerability in scan function in stdscan.c in nasm 2.15rc0 allows remote attackers to cause a denial of service via crafted asm file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-24514 โ€ผ

Cross-site Scripting (XSS) vulnerability in Visual Console Module of Pandora FMS could be used to hijack admin users session cookie values, carry out phishing attacks, etc. This issue affects Pandora FMS v767 version and prior versions on all platforms.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2020-25887 โ€ผ

Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-37424 โ€ผ

A vulnerability in the web-based management interfaceร‚ of EdgeConnect SD-WAN Orchestrator could allow anร‚ unauthenticated remote attacker to run arbitrary commands onร‚ the underlying host if certain preconditions outside of theร‚ attacker's control are met. Successful exploitation of thisร‚ vulnerability could allow an attacker to execute arbitraryร‚ commands on the underlying operating system leading toร‚ complete system compromise.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Controversial Cybercrime Law Passes in Jordan ๐Ÿ•ด

The increase in cyberattacks against the Middle East in the last few years has pressured Jordan and other nations to better secure their infrastructures.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Adobe Patches Critical Deserialization Vulnerability, but Exploits Persist ๐Ÿ•ด

The vulnerability was being exploited in the wild, targeting two versions of Adobe ColdFusion.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ Generative AI: Cybersecurity Weapon, But Not Without Adaptable, Creative (Human) Thinkers ๐Ÿฆฟ

Cybersecurity expert Kayne McGladrey speaks about why AI cannot do what creative people can, and the important role of generative AI in SOCs.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ•ด Study: More Than Half of Browser Extensions Pose Security Risks ๐Ÿ•ด

Spin.AI's risk assessment of some 300,000 browser extensions had overly permissive access and could execute potentially malicious behaviors.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-33850 โ€ผ

IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information. IBM X-Force ID: 257132.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ‘1
โ€ผ CVE-2023-38734 โ€ผ

IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481.

๐Ÿ“– Read

via "National Vulnerability Database".