πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ North Korea's State-Sponsored APTs Organize & Align πŸ•΄

An unprecedented collaboration by various APTs within the DPKR makes them harder to track, setting the stage for aggressive, complex cyberattacks that demand strategic response efforts, Mandiant warns.

πŸ“– Read

via "Dark Reading".
πŸ•΄ How Keyloggers Have Evolved From the Cold War to Today πŸ•΄

Keyloggers have been used for espionage since the days of the typewriter, but today's threats are easier to get and use than ever.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-37935 β€Ό

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET requests to those services.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-44995 β€Ό

Cross-Site Request Forgery (CSRF) vulnerability in WP Doctor WooCommerce Login Redirect plugin <=Γ‚ 2.2.4 versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37939 β€Ό

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] inΓ‚ FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all versions, may allow a local authenticated attacker with no Administrative privileges to retrieve the list ofΓ‚ files or folders excluded from malware scanning.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34993 β€Ό

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41675 β€Ό

A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27633 β€Ό

In FNET 4.6.3, TCP ISNs are improperly random.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-41838 β€Ό

An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36556 β€Ό

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34989 β€Ό

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43896 β€Ό

A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42787 β€Ό

A client-side enforcement of server-side security [CWE-602] vulnerabilityΓ‚ in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web console via client side code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36549 β€Ό

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted http get request parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-36555 β€Ό

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiOS 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands via the SAML and Security Fabric components.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-33301 β€Ό

An improper access control vulnerability in Fortinet FortiOS 7.2.0 - 7.2.4 and 7.4.0 allows an attacker to access a restricted resource from a non trusted host.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-34988 β€Ό

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get request parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-22298 β€Ό

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 through 2.0.1, FortiIsolator version 2.1.0 through 2.1.2, FortiIsolator version 2.2.0, FortiIsolator version 2.3.0 through 2.3.4 allows attacker to execute arbitrary OS commands in the underlying shell via specially crafted input parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-27631 β€Ό

In Oryx CycloneTCP 1.9.6, TCP ISNs are improperly random.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42788 β€Ό

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and version 6.2.0 through 6.2.11 may allow a local attacker with low privileges to execute unauthorized code via specifically crafted arguments to a CLI command

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42782 β€Ό

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via the knoweldge of an authorized device serial number.

πŸ“– Read

via "National Vulnerability Database".