πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ FBI, CISA Issue Joint Warning on 'Snatch' Ransomware-as-a-Service πŸ•΄

The group's use of malware that forces Windows computers to reboot into Safe Mode before encrypting files is noteworthy, advisory says.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Fake WinRAR PoC Exploit Conceals VenomRAT Malware πŸ•΄

A supposed exploit for a notable RCE vulnerability in the popular Windows file-archiving utility delivers a big sting for unwitting researchers and cybercriminals.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-20594 β€Ό

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43377 β€Ό

A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2023-43371 β€Ό

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43373 β€Ό

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43376 β€Ό

A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20597 β€Ό

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40368 β€Ό

IBM Storage Protect 8.1.0.0 through 8.1.19.0 could allow a privileged user to obtain sensitive information from the administrative command line client. IBM X-Force ID: 263456.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40618 β€Ό

A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39041 β€Ό

An information leak in KUKURUDELI Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43375 β€Ό

Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-39044 β€Ό

An information leak in ajino-Shiretoko Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43374 β€Ό

Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-40619 β€Ό

phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37410 β€Ό

IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22024 β€Ό

In the Unbreakable Enterprise Kernel (UEK), the RDS module in UEK has two setsockopt(2) options, RDS_CONN_RESET and RDS6_CONN_RESET, that are not re-entrant. A malicious local user with CAP_NET_ADMIN can use this to crash the kernel. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).

πŸ“– Read

via "National Vulnerability Database".