๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25K subscribers
88.4K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-45054 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in AWESOME TOGI Product Category Tree plugin <=ร‚ 2.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45064 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Daisuke Takahashi(Extend Wings) OPcache Dashboard plugin <=ร‚ 0.3.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5538 โ€ผ

The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45049 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <=ร‚ 4.6.7 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45057 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hitsteps Web Analytics plugin <=ร‚ 5.86 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45727 โ€ผ

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Data Security and Collaboration in the Modern Enterprise ๐Ÿ•ด

The CISO Survival Guide explores the complex and shifting challenges, perceptions, and innovations that will shape how organizations securely expand in the future.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Israeli Cybersecurity Startups: Impact of a Growing Conflict ๐Ÿ•ด

For Israeli startups and those closely linked to the country, the deepening crisis in the Middle East following the deadly Hamas attacks of Oct. 7 pose a fraught mix of complications.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Pro-Iranian Hacktivists Set Sights on Israeli Industrial Control Systems ๐Ÿ•ด

The hacktivists known as SiegedSec identify ICS targets, but there's no evidence of attacks yet.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด The Need for a Cybersecurity-Centric Business Culture ๐Ÿ•ด

Building a culture of cybersecurity is achievable by acknowledging its importance and consistently reinforcing that message.

๐Ÿ“– Read

via "Dark Reading".
โ™Ÿ๏ธ The Fake Browser Update Scam Gets a Makeover โ™Ÿ๏ธ

One of the oldest malware tricks in the book -- hacked websites claiming visitors need to update their Web browser before they can view any content -- has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware from being taken down by security experts or law enforcement: By hosting the malicious files on a decentralized, anonymous cryptocurrency blockchain.

๐Ÿ“– Read

via "Krebs on Security".
โ€ผ CVE-2023-45072 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kardi Order auto complete for WooCommerce plugin <=ร‚ 1.2.0 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46007 โ€ผ

Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32087 โ€ผ

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45070 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web รขโ‚ฌโ€œ Mobile-Friendly Drag & Drop Contact Form Builder plugin <=ร‚ 1.15.18 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46005 โ€ผ

Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45065 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit plugin <=ร‚ 1.42 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45071 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in 10Web Form Builder Team Form Maker by 10Web รขโ‚ฌโ€œ Mobile-Friendly Drag & Drop Contact Form Builder plugin <=ร‚ 1.15.18 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45073 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Michael Koch Mendeley Plugin plugin <=ร‚ 1.3.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-32088 โ€ผ

Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-31217 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MyTechTalky User Location and IP plugin <=ร‚ 1.6 versions.

๐Ÿ“– Read

via "National Vulnerability Database".