πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-36658 β€Ό

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. It has an unquoted service path that can be abused locally.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-32461 β€Ό

Dell PowerEdge BIOS and Dell Precision BIOS contain a buffer overflow vulnerability. A local malicious user with high privileges could potentially exploit this vulnerability, leading to corrupt memory and potentially escalate privileges. Γ‚ 

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3378 β€Ό

** REJECT ** This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4231 β€Ό

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cevik Informatics Online Payment System allows SQL Injection.This issue affects Online Payment System: before 4.09.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36659 β€Ό

An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Long inputs were not properly processed, which allows remote attackers to cause a denial of service (loss of communication).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How to Mitigate Cybersecurity Risks From Misguided Trust πŸ•΄

Trust is the crucial bridge between security and people, but excessive or misguided trust can pose serious security risks.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-3466 β€Ό

The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. For more details, see https://access.redhat.com/security/cve/CVE-2022-27652.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42270 β€Ό

Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Microsoft: 'Peach Sandstorm' Cyberattacks Target Defense, Pharmaceutical Orgs πŸ•΄

For months, the Iran-backed APT has carried out waves of password spray attacks attempting to authenticate to thousands of environments across multiple targets worldwide.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Greater Manchester Police Hack Follows Third-Party Supplier Fumble πŸ•΄

This incident bears notable resemblance to an attack that occurred just last month affecting London's Metropolitan Police, raising concerns over UK cybersecurity safeguards for public safety.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-28614 β€Ό

Freewill iFIS (aka SMART Trade) 20.01.01.04 allows OS Command Injection via shell metacharacters to a report page.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-47848 β€Ό

An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.13.01, BZ_2.02.07.09.13T, and BZ_2.02.07.09.09T, allows remote attackers to gain sensitive information via rootDesc.xml page of the UPnP service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42398 β€Ό

An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-38636 β€Ό

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Okta Flaw Involved in MGM Resorts Breach, Attackers Claim πŸ•΄

ALPHV/BlackCat ransomware operators have used their leak site to "set the record straight" about the MGM Resorts cyberattack. Meanwhile, more attacks abusing Okta could be likely.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-37263 β€Ό

Strapi is the an open-source headless content management system. Prior to version 4.12.1, field level permissions are not respected in the relationship title. If an actor has relationship title and the relationship shows a field they don't have permission to see, the field will still be visible. Version 4.12.1 has a fix for this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36479 β€Ό

Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Servlet for a binary with a space in its name, the servlet will escape the command by wrapping it in quotation marks. This wrapped command, plus an optional command prefix, will then be executed through a call to Runtime.exec. If the original binary name provided by the user contains a quotation mark followed by a space, the resulting command line will contain multiple tokens instead of one. This issue was patched in version 9.4.52, 10.0.16, 11.0.16 and 12.0.0-beta2.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36472 β€Ό

Strapi is the an open-source headless content management system. Prior to version 4.11.7, an unauthorized actor can get access to user reset password tokens if they have the configure view permissions. The `/content-manager/relations` route does not remove private fields or ensure that they can't be selected. This issue is fixed in version 4.11.7.

πŸ“– Read

via "National Vulnerability Database".