πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-32477 β€Ό

Dell Common Event Enabler 8.9.8.2 for Windows and prior, contain an improper access control vulnerability. A local low-privileged malicious user may potentially exploit this vulnerability to gain elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44469 β€Ό

A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3115 β€Ό

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On restrictions were not correctly enforced for indirect project members accessing public members-only project repositories.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-26146 β€Ό

All versions of the package ithewei/libhv are vulnerable to Cross-site Scripting (XSS) such that when a file with a name containing a malicious payload is served by the application, the filename is displayed without proper sanitization when it is rendered.

πŸ“– Read

via "National Vulnerability Database".
🦿 Protect Your Passwords for Life for Just $30 🦿

Automatically create and save passwords, fill in forms and logins, even securely share passwords and sync across all of your devices via WiFi.

πŸ“– Read

via "Tech Republic".
🦿 Censys Reveals Open Directories Share More Than 2,000 TB of Unprotected Data 🦿

These open directories could leak sensitive data, intellectual property or technical data and let an attacker compromise the entire system. Follow these security best practices for open directories.

πŸ“– Read

via "Tech Republic".
🦿 Best SIEM Tools and Software for 2023 🦿

Looking for the best SIEM tool? Check out our list and find the security information and event management solution that fits your business needs.

πŸ“– Read

via "Tech Republic".
πŸ“’ Should your business worry about North Korean cyber attacks? πŸ“’

The threat from North Korea should not be overlooked. What are its aims and how does it stack up against Russia and China?

πŸ“– Read

via "ITPro".
❀1
πŸ•΄ QR Code 101: What the Threats Look Like πŸ•΄

Because QR codes can be used for phishing as easily as an email or text can, organizations must remain vigilant when dealing with them.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5196 β€Ό

Mattermost fails to enforce character limits in all possible notification props allowing an attacker toΓ‚ send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5257 β€Ό

A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. VDB-240866 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5194 β€Ό

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for aΓ‚ system/user manager to demote / deactivate another manager

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5159 β€Ό

Mattermost fails to properly verify the permissions when managing/updating a bot allowing aΓ‚ User Manager role with user edit permissions to manage/update bots.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5193 β€Ό

Mattermost fails to properly check permissions when retrieving a post allowing forΓ‚ a System Role with the permission to manage channels to read the posts of a DM conversation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5195 β€Ό

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Cisco issues eight separate security advisories alerting customers to array of vulnerabilities πŸ“’

The advisory marks the end of a troubling week for Cisco with regard to security concerns

πŸ“– Read

via "ITPro".
πŸ•΄ Attacks on Azerbaijan Businesses Drop Malware via Fake Image Files πŸ•΄

Images purporting to be of the Armenia and Azerbaijan conflict were malware downloaders in disguise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ People Still Matter in Cybersecurity Management πŸ•΄

Cybersecurity's constant stream of shiny new things shouldn't distract managers from their focus on the people they're protecting.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5288 β€Ό

A remote unauthorized attacker may connect to the SIM1012, interact with the device andchange configuration settings. The adversary may also reset the SIM and in the worst case upload anew firmware version to the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43909 β€Ό

Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5261 β€Ό

A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".