πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32202 β€Ό

Walchem Intuition 9 firmware versions prior to v4.21 are vulnerable to improper authentication. Login credentials are stored in a format that could allow an attacker to use them as-is to login and gain access to the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36317 β€Ό

Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38422 β€Ό

Walchem Intuition 9 firmware versions prior to v4.21 are missing authentication for some of the API routes of the management web server. This could allow an attacker to download and export sensitive data.

πŸ“– Read

via "National Vulnerability Database".
⚠ Using WinRAR? Be sure to patch against these code execution bugs… ⚠

Imagine if you clicked on a harmless-looking image, but an unknown application fired up instead...

πŸ“– Read

via "Naked Security".
πŸ•΄ Prelude Security Tackles Continuous Security Testing in Containers πŸ•΄

Probes are tiny processes which run inside containers and scan applications for vulnerabilities.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-40573 β€Ό

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However, modifying or adding a job script to a document doesn't modify the content author. Together with a CSRF vulnerability in the job scheduler, this can be exploited for remote code execution by an attacker with edit right on the wiki. If the attack is successful, an error log entry with "Job content executed" will be produced. This vulnerability has been patched in XWiki 14.10.9 and 15.4RC1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32559 β€Ό

A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code, outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40572 β€Ό

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming right, thus compromising the confidentiality, integrity and availability of the whole XWiki installation. When a user with script right views this image and a log message `ERROR foo - Script executed!` appears in the log, the XWiki installation is vulnerable. This has been patched in XWiki 14.10.9 and 15.4RC1 by requiring a CSRF token for the actual page creation.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Salt Security lifts lid on new STEP partner program πŸ“’

Initiative's inaugural partners include Bright Security, Invicti, StackHawk, and Contrast Security

πŸ“– Read

via "ITPro".
πŸ•΄ eSentire Labs Open Sources Project to Monitor LLMs πŸ•΄

The eSentire LLM Gateway provides monitoring and governance of ChatGPT and other Large Language Models being used in the organization.

πŸ“– Read

via "Dark Reading".
πŸ•΄ North Korea's Lazarus Group Used GUI Framework to Build Stealthy RAT πŸ•΄

The world's most notorious threat actor is using an unprecedented tactic for sneaking spyware into the IT networks of important companies.

πŸ“– Read

via "Dark Reading".
πŸ“’ β€˜Worst case scenario’ ransomware attack cripples Danish cloud provider πŸ“’

Hundreds of customers in the Nordics have been impacted by the breach

πŸ“– Read

via "ITPro".
🦿 Critical Insight Reports Fewer Cybersecurity Breaches in Health Care, Yet Victim Numbers Are Up in 2023 🦿

A new study by Critical Insight shows that cybersecurity attacks in the health care sector are hitting more individuals and finding vulnerabilities in third-party partners.

πŸ“– Read

via "Tech Republic".
πŸ•΄ 5 Best Practices for Implementing Risk-First Cybersecurity πŸ•΄

Embracing a risk-first mindset empowers organizations to make informed decisions, strengthen security, safeguard valuable assets, and reduce financial impact.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34040 β€Ό

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers.Specifically, an application is vulnerable when all of the following are true: * The user does notΓ‚ configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topicBy default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32516 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GloriaFood Restaurant Menu Γ’β‚¬β€œ Food Ordering System Γ’β‚¬β€œ Table Reservation plugin <=Γ‚ 2.3.6 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32511 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Booking Ultra Pro Booking Ultra Pro Appointments Booking Calendar Plugin plugin <=Γ‚ 1.1.8 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32510 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Rolf van Gelder Order Your Posts Manually plugin <=Γ‚ 2.2.5 versions.

πŸ“– Read

via "National Vulnerability Database".
πŸ›  Wireshark Analyzer 4.0.8 πŸ› 

Wireshark is a GTK+-based network protocol analyzer that lets you capture and interactively browse the contents of network frames. The goal of the project is to create a commercial-quality analyzer for Unix and Win32 and to give Wireshark features that are missing from closed-source sniffers. This is the source code release.

πŸ“– Read

via "Packet Storm Security".
🦿 How to Remove a Lost Device From Your Google Account 🦿

Follow this guide to learn how to easily remove any device from your Google account and keep your account secure.

πŸ“– Read

via "Tech Republic".
🦿 Google AI in Workspace Adds New Zero-Trust and Digital Sovereignty Controls 🦿

Google announced security enhancements to Google Workspace focused on enhancing threat defense controls with Google AI.

πŸ“– Read

via "Tech Republic".