🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2023-38557

A vulnerability has been identified in Spectrum Power 7 (All versions < V23Q3). The affected product assigns improper access rights to the update script. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges.

📖 Read

via "National Vulnerability Database".
CVE-2023-38558

A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration Console) V4.0 Update 1 (All versions). The affected application leaks Windows admin credentials. An attacker with local access to the Administration Console could get the credentials, and impersonate the admin user, thereby gaining admin access to other Windows systems.

📖 Read

via "National Vulnerability Database".
🕴 'Scattered Spider' Behind MGM Cyberattack, Targets Casinos 🕴

The ransomware group is a collection of young adults, and also recently breached Caesars Entertainment and made a ransom score in the tens of millions range.

📖 Read

via "Dark Reading".
🦿 Conversational AI Company Uniphore Leverages Red Box Acquisition for New Data Collection Tool 🦿

Red Box provides the open architecture for data capture. Uniphore then feeds that data into U-Capture, its conversational AI automation tool.

📖 Read

via "Tech Republic".
🕴 Professional Sports: The Next Frontier of Cybersecurity? 🕴

Sports teams, major leagues, global sporting associations, and entertainment venues are all home to valuable personal and business data. Here's how to keep them safe.

📖 Read

via "Dark Reading".
🛠 Suricata IDPE 7.0.1 🛠

Suricata is a network intrusion detection and prevention engine developed by the Open Information Security Foundation and its supporting vendors. The engine is multi-threaded and has native IPv6 support. It's capable of loading existing Snort rules and signatures and supports the Barnyard and Barnyard2 tools.

📖 Read

via "Packet Storm Security".
👍1
🕴 Cybersecurity and Compliance in the Age of AI 🕴

It takes a diverse village of experts to enact effective cybersecurity guidelines, practices, and processes.

📖 Read

via "Dark Reading".
CVE-2023-2848

Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This was the result of a missing header validation.

📖 Read

via "National Vulnerability Database".
🕴 Mideast Retailers Dogged by Scam Facebook Pages Offering 'Investment' Opportunities 🕴

Around 900 pages were identified as using Arabic language and familiar brand names to snare users and steal their money and personal details — presenting big brand protection issues for retailers.

📖 Read

via "Dark Reading".
CVE-2023-30909

A remote authentication bypass issue exists in someOneView APIs.

📖 Read

via "National Vulnerability Database".
CVE-2021-28485

Ericsson Mobile Switching Center Server (MSC-S) BC 18A and IS 3.1 releases before IS 3.1 CP22 allows Directory Traversal.

📖 Read

via "National Vulnerability Database".
CVE-2023-1108

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

📖 Read

via "National Vulnerability Database".
🕴 How to Transform Security Awareness Into Security Culture 🕴

Leverage the human layer as a crucial cog in building cyber resilience within the organization.

📖 Read

via "Dark Reading".
🕴 Stealer Thugs Behind RedLine & Vidar Pivot to Ransomware 🕴

In a notable shift in strategy, the threat actors are abusing code-signing certificates to spread a double whammy of infostealers and ransomware payloads.

📖 Read

via "Dark Reading".
CVE-2023-42178

Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.

📖 Read

via "National Vulnerability Database".
CVE-2023-36250

CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2023-42180

An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file.

📖 Read

via "National Vulnerability Database".
CVE-2023-4951

A cross site scripting issue was discovered with the pagination function on the "Client-based Authentication Policy Configuration" screen of the GreenRADIUS web admin interface. This issue is found in GreenRADIUS v5.1.1.1 and prior. A fix was included in v5.1.2.2.

📖 Read

via "National Vulnerability Database".
🦿 New DarkGate Malware Campaign Hits Companies Via Microsoft Teams 🦿

Get technical details about how this new attack campaign is delivered via Microsoft Teams and how to protect your company from this loader malware.

📖 Read

via "Tech Republic".
👍1
🕴 Cuba Ransomware Gang Continues to Evolve With Dangerous Backdoor 🕴

The Russian-speaking ransomware gang continues to update its tactics while managing to steal highly sensitive information from its victims.

📖 Read

via "Dark Reading".
🦿 Zero-Day Security Vulnerability Found in Chrome, Firefox and Other Browsers 🦿

Updates are now available to patch a Chrome vulnerability that would allow attackers to run malicious code.

📖 Read

via "Tech Republic".
👍1