πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-41993 β€Ό

The issue was addressed with improved checks. This issue is fixed in Safari 16.6.1, macOS Ventura 13.6, OS 17.0.1 and iPadOS 17.0.1, iOS 16.7 and iPadOS 16.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 'Gold Melody' Access Broker Plays on Unpatched Servers' Strings πŸ•΄

A financially motivated threat actor uses known vulnerabilities, ordinary TTPs, and off-the-shelf tools to exploit the unprepared, highlighting the fact that many organizations still don't focus on the security basics.

πŸ“– Read

via "Dark Reading".
πŸ•΄ What Does Socrates Have to Do With CPM? πŸ•΄

It's time to focus on the "P" in cybersecurity performance management.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Mysterious 'Sandman' APT Targets Telecom Sector With Novel Backdoor πŸ•΄

The Sandman group's main malware is among the very few that use the Lua scripting language and its just-in-time compiler.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-34576 β€Ό

SQL injection vulnerability in updatepos.php in PrestaShop opartfaq through 1.0.3 allows remote attackers to run arbitrary SQL commands via unspedified vector.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38343 β€Ό

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side Request Forgery.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42482 β€Ό

Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-38344 β€Ό

An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed via /landesk/managementsuite/core/core.secure/OsdScript.asmx. The application does not sufficiently restrict user-supplied paths, allowing for an authenticated attacker to read arbitrary files from a remote system, including the private key used to authenticate to agents for remote access.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42261 β€Ό

Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43128 β€Ό

D-LINK DIR-806 1200M11AC wireless router DIR806A1_FW100CNb11 is vulnerable to command injection due to lax filtering of HTTP_ST parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4504 β€Ό

Due to failure in validating the length provided by an attacker-crafted PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in CUPS version 2.4.7, released in September of 2023.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31719 β€Ό

FUXA <= 1.1.12 is vulnerable to SQL Injection via /api/signin.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31717 β€Ό

A SQL Injection attack in FUXA <= 1.1.12 allows exfiltration of confidential information from the database.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23362 β€Ό

An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability allows remote authenticated users to execute commands via susceptible QNAP devices.We have already fixed the vulnerability in the following versions:QTS 5.0.1.2376 build 20230421 and laterQTS 4.5.4.2374 build 20230416 and laterQuTS hero h5.0.1.2376 build 20230421 and laterQuTS hero h4.5.4.2374 build 20230417 and laterQuTScloud c5.0.1.2374 and later

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23364 β€Ό

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.We have already fixed the vulnerability in the following versions:Multimedia Console 2.1.1 ( 2023/03/29 ) and laterMultimedia Console 1.4.7 ( 2023/03/20 ) and later

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31718 β€Ό

FUXA <= 1.1.12 is vulnerable to Local via Inclusion via /api/download.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-23363 β€Ό

A buffer copy without checking size of input vulnerability has been reported to affect QNAP operating system. If exploited, the vulnerability possibly allows remote users to execute code via unspecified vectors.We have already fixed the vulnerability in the following versions:QTS 4.3.6.2441 build 20230621 and laterQTS 4.3.3.2420 build 20230621 and laterQTS 4.2.6 build 20230621 and laterQTS 4.3.4.2451 build 20230621 and later

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31716 β€Ό

FUXA <= 1.1.12 has a Local File Inclusion vulnerability via file=fuxa.log

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Guardians of the Cyberverse: Building a Resilient Security Culture πŸ•΄

Whether achieved through AI-enabled automation, proactive identification and resolution of issues, or the equitable distribution of risk management responsibilities, the goal must be resilience.

πŸ“– Read

via "Dark Reading".
πŸ•΄ ASPM Is Good, But It's Not a Cure-All for App Security πŸ•΄

What application security posture management does, it does well. But you'll still need to fill in some holes, especially concerning API security.

πŸ“– Read

via "Dark Reading".