๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25K subscribers
88.4K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
โ€ผ CVE-2023-45608 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Nicola Modugno Smart Cookie Kit plugin <=ร‚ 2.3.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿฆฟ What Australian IT Leaders Need to Focus on Ahead of Privacy Act Reforms ๐Ÿฆฟ

The Australian federal government aims to deliver changes to privacy laws in 2024. Organisations are being warned to prepare ahead of time by creating a comprehensive map of organisational data.

๐Ÿ“– Read

via "Tech Republic".
โ€ผ CVE-2023-45607 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Hector Cabrera WordPress Popular Posts plugin <=ร‚ 6.3.2 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45630 โ€ผ

Unauth. Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Gallery รขโ‚ฌโ€œ Image and Video Gallery with Thumbnails plugin <=ร‚ 2.0.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45604 โ€ผ

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Scott Reilly Get Custom Field Values plugin <=ร‚ 4.0.1 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-30781 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Theme Blvd Tweeple plugin <=ร‚ 0.9.5 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-5631 โ€ผ

Roundcube before 1.4.15, 1.5.x before 1.5.5, and 1.6.x before 1.6.4 allows stored XSS via an HTML e-mail message with a crafted SVG document because of program/lib/Roundcube/rcube_washtml.php behavior. This could allow a remote attackerto load arbitrary JavaScript code.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45602 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <=ร‚ 5.785 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45632 โ€ผ

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <=ร‚ 1.5.22 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45628 โ€ผ

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in QROkes QR Twitter Widget plugin <=ร‚ 0.2.3 versions.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด North Korea's Kimsuky Doubles Down on Remote Desktop Control ๐Ÿ•ด

The sophisticated APT employs various tactics to abuse Windows and other built-in protocols with both custom and public malware to take over victim systems.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ ExpressVPN Review (2023): Pricing, Features, Pros, & Cons ๐Ÿฆฟ

Editor has the option to alter SEO's meta description or write their own DEK to draw readers into the article most effectively. Alternatively, editor can assign DEK writing to the assigned writer. Consider the top picks or major editorial call-outs for inclusion.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ•ด D-Link Confirms Breach, Rebuts Hacker's Claims About Scope ๐Ÿ•ด

The router specialist says the attacker's claims to have heisted millions and millions of records are significantly overblown. But an incident did happen, stemming from a successful phish.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด What CISOs Should Exclude From SEC Cybersecurity Filings ๐Ÿ•ด

Should CISOs include only known information in the SEC filings for a material security incident, or is there room to include details that may change during the investigation?

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2023-35656 โ€ผ

In multiple functions of protocolembmsadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45813 โ€ผ

Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_link function` uses the python-validators URL validation regex. This particular regular expression has an exponential complexity which allows an attacker to cause an application crash using a well-crafted argument. An attacker can use a well-crafted URL argument to exploit the vulnerability in the regular expression and cause a Denial of Service on the system. The validators file has been removed in version 4.0.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-4601 โ€ผ

A stack-based buffer overflow vulnerability exists in NI System Configuration that could result in information disclosure and/or arbitrary code execution. Successful exploitation requires that an attacker can provide a specially crafted response. This affects NI System Configuration 2023 Q3 and all previous versions.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-43803 โ€ผ

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/tools/installed` and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. This issue has been addressed in version `1.3.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35663 โ€ผ

In Init of protocolnetadapter.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-43802 โ€ผ

Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload` which handles request with the `filename` parameter. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can escalate their privileges to those of the user running the Arduino Create Agent service via a crafted HTTP POST request. This issue has been addressed in version `1.3.3`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45145 โ€ผ

Redis is an in-memory database that persists on disk. On startup, Redis begins listening on a Unix socket before adjusting its permissions to the user-provided configuration. If a permissive umask(2) is used, this creates a race condition that enables, during a short period of time, another process to establish an otherwise unauthorized connection. This problem has existed since Redis 2.6.0-RC1. This issue has been addressed in Redis versions 7.2.2, 7.0.14 and 6.2.14. Users are advised to upgrade. For users unable to upgrade, it is possible to work around the problem by disabling Unix sockets, starting Redis with a restrictive umask, or storing the Unix socket file in a protected directory.

๐Ÿ“– Read

via "National Vulnerability Database".