πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
24.9K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-44824 β€Ό

An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45004 β€Ό

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in wp3sixty Woo Custom Emails plugin <=Γ‚ 2.2 versions.

πŸ“– Read

via "National Vulnerability Database".
🦿 Is Collaboration The Key To Aussie Tech Challenges? 🦿

As Australian organisations and government departments continue to struggle with IT resourcing, a new wave of collaboration potentially represents the solution.

πŸ“– Read

via "Tech Republic".
🦿 Software Supply Chain Security Attacks Up 200%: New Sonatype Research 🦿

Sonatype's 9th annual State of the Software Supply Chain also covers regulations and how AI could help developers protect organizations from security risks.

πŸ“– Read

via "Tech Republic".
β€Ό CVE-2023-45901 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45903 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-37537 β€Ό

An unquoted service path vulnerability in HCL AppScan Presence, deployed as a Windows service in HCL AppScan on Cloud (ASoC), may allow a local attacker to gain elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45904 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45906 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45907 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-20598 β€Ό

An improper privilege management in the AMD RadeonΓ’β€žΒ’Γ‚ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45902 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-43959 β€Ό

An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-45905 β€Ό

Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.

πŸ“– Read

via "National Vulnerability Database".
β™ŸοΈ Tech CEO Sentenced to 5 Years in IP Address Scheme β™ŸοΈ

Amir Golestan, the 40-year-old CEO of the Charleston, S.C. based technology company Micfo LLC, has been sentenced to five years in prison for wire fraud. Golestan's sentencing comes nearly two years after he pleaded guilty to using an elaborate network of phony companies to secure more than 735,000 Internet Protocol (IP) addresses from the American Registry for Internet Numbers (ARIN), the nonprofit which oversees IP addresses assigned to entities in the U.S., Canada, and parts of the Caribbean.

πŸ“– Read

via "Krebs on Security".
❀1
πŸ•΄ Watch Out: Attackers Are Hiding Malware in 'Browser Updates' πŸ•΄

Updating your browser when prompted is a good practice, just make sure the notification comes from the vendor themselves.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-27133 β€Ό

TSplus Remote Work 16.0.0.0 has weak permissions for .exe, .js, and .html files under the %PROGRAMFILES(X86)%\TSplus-RemoteWork\Clients\www folder. This may enable privilege escalation if a different local user modifies a file. NOTE: CVE-2023-31067 and CVE-2023-31068 are only about the TSplus Remote Access product, not the TSplus Remote Work product.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27132 β€Ό

TSplus Remote Work 16.0.0.0 places a cleartext password on the "var pass" line of the HTML source code for the secure single sign-on web portal. NOTE: CVE-2023-31069 is only about the TSplus Remote Access product, not the TSplus Remote Work product.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ UAE, US Partner to Bolster Financial Services Cybersecurity πŸ•΄

The two countries agree to share financial services information and provide cross-border training and best practices.

πŸ“– Read

via "Dark Reading".
πŸ•΄ 'Etherhiding' Blockchain Technique Masks Malicious Code in WordPress Sites πŸ•΄

The ClearFake campaign uses fake browser updates to lure victims and spread RedLine, Amadey, and Lumma stealers.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Zero-Day Alert: Ten Thousand Cisco IOS XE Systems Now Compromised πŸ•΄

Just a day after Cisco disclosed CVE-2023-20198, it remains unpatched, and one vendor says a Shodan scan shows at least 10,000 Cisco devices with an implant for arbitrary code execution on them. The vendor meanwhile has updated the advisory with more mitigation steps.

πŸ“– Read

via "Dark Reading".