πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ QR Code 101: What the Threats Look Like πŸ•΄

Because QR codes can be used for phishing as easily as an email or text can, organizations must remain vigilant when dealing with them.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5196 β€Ό

Mattermost fails to enforce character limits in all possible notification props allowing an attacker toΓ‚ send a really long value for a notification_prop resulting in the server consuming an abnormal quantity of computing resources and possibly becoming temporarily unavailable for its users.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5257 β€Ό

A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. VDB-240866 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5194 β€Ό

Mattermost fails to properly validate permissions when demoting and deactivating a user allowing for aΓ‚ system/user manager to demote / deactivate another manager

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5159 β€Ό

Mattermost fails to properly verify the permissions when managing/updating a bot allowing aΓ‚ User Manager role with user edit permissions to manage/update bots.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5193 β€Ό

Mattermost fails to properly check permissions when retrieving a post allowing forΓ‚ a System Role with the permission to manage channels to read the posts of a DM conversation.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5195 β€Ό

Mattermost fails to properly validate the permissions when soft deleting a team allowing a team member to soft delete other teams that they are not part of

πŸ“– Read

via "National Vulnerability Database".
πŸ“’ Cisco issues eight separate security advisories alerting customers to array of vulnerabilities πŸ“’

The advisory marks the end of a troubling week for Cisco with regard to security concerns

πŸ“– Read

via "ITPro".
πŸ•΄ Attacks on Azerbaijan Businesses Drop Malware via Fake Image Files πŸ•΄

Images purporting to be of the Armenia and Azerbaijan conflict were malware downloaders in disguise.

πŸ“– Read

via "Dark Reading".
πŸ•΄ People Still Matter in Cybersecurity Management πŸ•΄

Cybersecurity's constant stream of shiny new things shouldn't distract managers from their focus on the people they're protecting.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5288 β€Ό

A remote unauthorized attacker may connect to the SIM1012, interact with the device andchange configuration settings. The adversary may also reset the SIM and in the worst case upload anew firmware version to the device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43909 β€Ό

Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5261 β€Ό

A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43944 β€Ό

A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5260 β€Ό

A vulnerability, which was classified as critical, has been found in SourceCodester Simple Membership System 1.0. This issue affects some unknown processing of the file group_validator.php. The manipulation of the argument club_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240869 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5258 β€Ό

A vulnerability classified as critical has been found in OpenRapid RapidCMS 1.3.1. This affects an unknown part of the file /resource/addgood.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240867.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5259 β€Ό

A vulnerability classified as problematic was found in ForU CMS. This vulnerability affects unknown code of the file /admin/cms_admin.php. The manipulation of the argument del leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The identifier of this vulnerability is VDB-240868.

πŸ“– Read

via "National Vulnerability Database".
🦿 ZenRAT Malware Targets Windows Users Via Fake Bitwarden Password Manager Installation Package 🦿

We talked to Proofpoint researchers about this new malware threat and how it infects Windows systems to steal information.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-5262 β€Ό

A vulnerability has been found in OpenRapid RapidCMS 1.3.1 and classified as critical. Affected by this vulnerability is the function isImg of the file /admin/config/uploadicon.php. The manipulation of the argument fileName leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240871.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41662 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ulf Benjaminsson WP-dTree plugin <=Γ‚ 4.4.5 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41691 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <=Γ‚ 6.3.1 versions.

πŸ“– Read

via "National Vulnerability Database".