πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-38354 β€Ό

MiniTool Movie Maker 4.1 contains an insecure installation process that allows attackers to achieve remote code execution through a man in the middle attack.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43566 β€Ό

In JetBrains TeamCity before 2023.05.4 stored XSS was possible during nodes configuration

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ MGM, Caesars Face Regulatory, Legal Maze After Cyber Incidents πŸ•΄

MGM and Caesars are putting new SEC incident disclosure regulations to a real-world test in the aftermath of twin cyberattacks on the casinos, as class-action lawsuits loom.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Trend Micro Patches Zero-Day Endpoint Vulnerability πŸ•΄

The critical vulnerability involves uninstalling third-party security products and has been used in cyberattacks.

πŸ“– Read

via "Dark Reading".
πŸ•΄ China-Linked Actor Taps Linux Backdoor in Forceful Espionage Campaign πŸ•΄

"SprySOCKS" melds features from multiple previously known badware and adds to the threat actor's growing malware arsenal, Trend Micro says.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-2995 β€Ό

The Leyka WordPress plugin through 3.30.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4376 β€Ό

The Serial Codes Generator and Validator with WooCommerce Support WordPress plugin before 2.4.15 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
πŸ”₯1
β€Ό CVE-2023-25529 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a leak of another userÒ€ℒs session token by observing timing discrepancies between server responses. A successful exploit of this vulnerability may lead to information disclosure, escalation of privileges, and data tampering.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25534 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25527 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel memory. A successful exploit of this vulnerability may lead to arbitrary kernel code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4088 β€Ό

Incorrect Default Permissions vulnerability due to incomplete fix to address CVE-2020-14496 in Mitsubishi Electric Corporation FA engineering software products allows a malicious local attacker to execute a malicious code, which could result in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. However, if the mitigated version described in the advisory for CVE-2020-14496 is used and installed in the default installation folder, this vulnerability does not affect the products.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25528 β€Ό

NVIDIA DGX H100 baseboard management controller (BMC) contains a vulnerability in a web server plugin, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31008 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to code execution, denial of services, escalation of privileges, and information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25525 β€Ό

NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31011 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25526 β€Ό

NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may cause an uncaught exception by injecting a crafted packet. A successful exploit may lead to denial of service.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-31010 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, and denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31015 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36319 β€Ό

File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-25532 β€Ό

NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to information disclosure.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5063 β€Ό

The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸ“– Read

via "National Vulnerability Database".