πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-38204 β€Ό

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38206 β€Ό

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints resulting in a low-confidentiality impact. Exploitation of this issue does not require user interaction.

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Dutch football association admits paying LockBit in β€˜April Fools’ ransomware attack πŸ“’

The national governing body offered a rare candid account of the ransomware attack, the full scale of which is still unknown

πŸ“– Read

via "ITPro".
β€Ό CVE-2023-38557 β€Ό

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38558 β€Ό

A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'Scattered Spider' Behind MGM Cyberattack, Targets Casinos πŸ•΄

The ransomware group is a collection of young adults, and also recently breached Caesars Entertainment and made a ransom score in the tens of millions range.

πŸ“– Read

via "Dark Reading".
🦿 Conversational AI Company Uniphore Leverages Red Box Acquisition for New Data Collection Tool 🦿

Red Box provides the open architecture for data capture. Uniphore then feeds that data into U-Capture, its conversational AI automation tool.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Professional Sports: The Next Frontier of Cybersecurity? πŸ•΄

Sports teams, major leagues, global sporting associations, and entertainment venues are all home to valuable personal and business data. Here's how to keep them safe.

πŸ“– Read

via "Dark Reading".
πŸ›  Suricata IDPE 7.0.1 πŸ› 

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

πŸ“– Read

via "Packet Storm Security".
πŸ‘1
πŸ•΄ Cybersecurity and Compliance in the Age of AI πŸ•΄

It takes a diverse village of experts to enact effective cybersecurity guidelines, practices, and processes.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2848 β€Ό

Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mideast Retailers Dogged by Scam Facebook Pages Offering 'Investment' Opportunities πŸ•΄

Around 900 pages were identified as using Arabic language and familiar brand names to snare users and steal their money and personal details β€” presenting big brand protection issues for retailers.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-30909 β€Ό

A remote authentication bypass issue exists in someOneView APIs.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-28485 β€Ό

Ericsson Mobile Switching Center Server (MSC-S) BC 18A and IS 3.1 releases before IS 3.1 CP22 allows Directory Traversal.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-1108 β€Ό

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Transform Security Awareness Into Security Culture πŸ•΄

Leverage the human layer as a crucial cog in building cyber resilience within the organization.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Stealer Thugs Behind RedLine & Vidar Pivot to Ransomware πŸ•΄

In a notable shift in strategy, the threat actors are abusing code-signing certificates to spread a double whammy of infostealers and ransomware payloads.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-42178 β€Ό

Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36250 β€Ό

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-42180 β€Ό

An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4951 β€Ό

A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface.Γ‚ This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.

πŸ“– Read

via "National Vulnerability Database".