πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
🦿 Cyberghost VPN Review (2023): Features, Pricing, and Security 🦿

In this comprehensive review of Cyberghost VPN, we cover its features, pricing, security, and overall performance. Find out if this is the right VPN for you.

πŸ“– Read

via "Tech Republic".
πŸ•΄ KillNet Claims DDoS Attack Against Royal Family Website πŸ•΄

The royal takedown was a brief but effective PR stunt for Russia's most notorious hacktivist group.

πŸ“– Read

via "Dark Reading".
πŸ•΄ North Korea Poses as Meta to Deploy Complex Backdoor at Aerospace Org πŸ•΄

The Lazarus Group's "LightlessCan" malware executes multiple native Windows commands within the RAT itself, making detection significantly harder, security vendor says.

πŸ“– Read

via "Dark Reading".
🦿 Common Errors When Connecting Multiple iPhones to One Apple ID 🦿

Surprises often arise when connecting two iPhones to the same Apple ID. Addressing several key settings helps avoid common mistakes.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-44463 β€Ό

An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43361 β€Ό

Buffer Overflow vulnerability in Vorbis-tools v.1.4.2 allows a local attacker to execute arbitrary code and cause a denial of service during the conversion of wav files to ogg files.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43267 β€Ό

A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43836 β€Ό

There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44009 β€Ό

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43835 β€Ό

Super Store Finder 3.7 and below is vulnerable to authenticated Arbitrary PHP Code Injection that could lead to Remote Code Execution when settings overwrite config.inc.php content.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43890 β€Ό

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43268 β€Ό

Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44008 β€Ό

File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-3592 β€Ό

In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43297 β€Ό

An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5344 β€Ό

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44011 β€Ό

An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-31042 β€Ό

A flaw exists in FlashBlade Purity whereby an authenticated user with access to FlashBladeÒ€ℒs object store protocol can impact the availability of the systemÒ€ℒs data access and replication protocols.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43980 β€Ό

Presto Changeo testsitecreator up to v1.1.1 was discovered to contain a SQL injection vulnerability via the component disable_json.php.

πŸ“– Read

via "National Vulnerability Database".