πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32591 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Cloud Primero B.V DBargain plugin <=Γ‚ 3.0.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32756 β€Ό

e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but canÒ€ℒt control system or disrupt service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32757 β€Ό

e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ FBI alerts Barracuda customers after ineffective patch πŸ“’

Despite issuing a patch in May, Barracuda ESG appliance users are still at high risk

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-32575 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PI Websolution Product page shipping calculator for WooCommerce plugin <=Γ‚ 1.3.25 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32596 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wolfgang Ertl weebotLite plugin <=Γ‚ 1.0.0 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4478 β€Ό

Mattermost fails to restrict which parameters' values it takes from the request during signup allowing an attacker to register users as inactive, thus blocking them from later accessing Mattermost without the system admin activating their accounts.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32595 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Palasthotel by Edward Bock, Katharina Rompf Sunny Search plugin <=Γ‚ 1.0.2 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25981 β€Ό

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form plugin <=Γ‚ 2.8.1 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-24394 β€Ό

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy iframe popup plugin <=Γ‚ 3.3 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25649 β€Ό

There is a command injection vulnerability in a mobile internet product of ZTE. Due to insufficient validation of SET_DEVICE_LED interface parameter, an authenticated attacker could use the vulnerability to execute arbitrary commands.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Is Bias in AI Algorithms a Threat to Cloud Security? πŸ•΄

Using AI for threat detection and response is essential β€” but it can't replace human intelligence, expertise, and intuition.

πŸ“– Read

via "Dark Reading".
πŸ“’ NIST aims to quantum-proof encryption with new algorithms πŸ“’

Three algorithms are now in draft and more are on the way to bolster enterprise defenses

πŸ“– Read

via "ITPro".
πŸ“’ Encouraging a security-first mindset πŸ“’

Security has to be seen from a business perspective as well as a technical one

πŸ“– Read

via "ITPro".
β™ŸοΈ Kroll Employee SIM-Swapped for Crypto Investor Data β™ŸοΈ

Security consulting giant Kroll disclosed today that a SIM-swapping attack against one of its employees led to the theft of user information for multiple cryptocurrency platforms that are relying on Kroll services in their ongoing bankruptcy proceedings. And there are indications that fraudsters may already be exploiting the stolen data in phishing attacks.Cryptocurrency lender BlockFi and the now-collapsed crypto trading platform FTX each disclosed data breaches this week thanks to a recent SIM-swapping attack targeting an employee of Kroll -- the company handling both firms' bankruptcy restructuring.

πŸ“– Read

via "Krebs on Security".
πŸ•΄ 'Whiffy Recon' Malware Transmits Device Location Every 60 Seconds πŸ•΄

Deployed by the infamous SmokeLoader botnet, the location-tracking malware could be used for a host of follow-on cyberattacks or even physical targeting.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-40797 β€Ό

In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38201 β€Ό

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake agent is added to the verifier list by a legitimate user, resulting in a breach of the integrity of the registrar database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-11711 β€Ό

An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious HTML content in order to execute JavaScript inside a victim's browser. This results in a stored XSS on the authentication interface of the admin panel. Moreover, an unsecured authentication form is present on the authentication interface of the SSL VPN captive portal. Users are allowed to save their credentials inside the browser. If an administrator saves his credentials through this unsecured form, these credentials could be stolen via the stored XSS on the admin panel without user interaction. Another possible exploitation would be modification of the authentication form of the admin panel into a malicious form.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40796 β€Ό

Phicomm k2 v22.6.529.216 is vulnerable to command injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40798 β€Ό

In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability.

πŸ“– Read

via "National Vulnerability Database".