๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.8K subscribers
89.2K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด 23andMe Cyberbreach Exposes DNA Data, Potential Family Ties ๐Ÿ•ด

The information leaked in the breach involves personally identifiable information as well as genetic ancestry data, potential relatives, and geolocations.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-44243 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <=ร‚ 1.2.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23370 โ€ผ

An insufficiently protected credentials vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to gain access to user accounts and access sensitive data used by the user account via unspecified vectors.We have already fixed the vulnerability in the following version:QVPN Windows 2.1.0.0518 and later

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44807 โ€ผ

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the cancelPing function.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23365 โ€ผ

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.We have already fixed the vulnerability in the following version:Music Station 5.3.22 and later

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-44233 โ€ผ

Cross-Site Request Forgery (CSRF) vulnerability in FooPlugins Best WordPress Gallery Plugin รขโ‚ฌโ€œ FooGallery plugin <=ร‚ 2.2.44 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32971 โ€ผ

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.We have already fixed the vulnerability in the following versions:QTS 5.0.1.2425 build 20230609 and laterQTS 5.1.0.2444 build 20230629 and laterQTS 4.5.4.2467 build 20230718 and laterQuTS hero h5.0.1.2515 build 20230907 and laterQuTS hero h5.1.0.2424 build 20230609 and laterQuTS hero h4.5.4.2476 build 20230728 and laterQuTScloud c5.1.0.2498 and later

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32972 โ€ผ

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network.We have already fixed the vulnerability in the following versions:QTS 5.0.1.2425 build 20230609 and laterQTS 5.1.0.2444 build 20230629 and laterQTS 4.5.4.2467 build 20230718 and laterQuTS hero h5.0.1.2515 build 20230907 and laterQuTS hero h5.1.0.2424 build 20230609 and laterQuTS hero h4.5.4.2476 build 20230728 and laterQuTScloud c5.1.0.2498 and later

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23366 โ€ผ

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow authenticated users to read the contents of unexpected files and expose sensitive data via a network.We have already fixed the vulnerability in the following version:Music Station 5.3.22 and later

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-39928 โ€ผ

A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-23371 โ€ผ

A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated administrators to read sensitive data via unspecified vectors.We have already fixed the vulnerability in the following version:QVPN Windows 2.2.0.0823 and later

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ IPVanish VPN Review (2023): Features, Pricing, and Security ๐Ÿฆฟ

Read our comprehensive review of IPVanish VPN. Discover its features, pricing, and more to determine if it meets your online security and privacy needs.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ•ด Predictive Analysis Can Reduce Risks Associated With Data Breaches ๐Ÿ•ด



๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด SecTor 2023: Full Schedule Programming for Toronto Event ๐Ÿ•ด



๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Cybersecurity Funding Rises by 21% in Q3 2023, Pinpoint Search Group's Report Indicates ๐Ÿ•ด



๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด RIT Is the First University to Receive Support From the Google Cybersecurity Clinics Fund ๐Ÿ•ด



๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-21266 โ€ผ

In killBackgroundProcesses of ActivityManagerService.java, there is a possible way to escape Google Play protection due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5366 โ€ผ

A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-21291 โ€ผ

In visitUris of Notification.java, there is a possible way to reveal image contents from another user due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5214 โ€ผ

In Puppet Bolt versions prior to 3.27.4, a path to escalate privileges was identified.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-21244 โ€ผ

In visitUris of Notification.java, there is a possible bypass of user profile boundaries due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".