πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-5570 β€Ό

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in Inohom Home Manager Gateway allows Account Footprinting.This issue affects Home Manager Gateway: before v.1.27.12.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5821 β€Ό

The Thumbnail carousel slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the deleteselected function. This makes it possible for unauthenticated attackers to delete sliders in bulk via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5820 β€Ό

The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the addedit functionality. This makes it possible for unauthenticated attackers to upload arbitrary files via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5443 β€Ό

Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting.This issue affects E-invoice: before 2.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46604 β€Ό

Apache ActiveMQ is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker with network access to a broker to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiateΓ‚ any class on the classpath.Γ‚ Users are recommended to upgrade to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3, which fixes this issue.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46394 β€Ό

A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46393 β€Ό

gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Hacktivist Activity Related to Gaza Conflict Dwindles πŸ•΄

Groups have fallen silent after bold claims of action at the start of the conflict.

πŸ“– Read

via "Dark Reading".
🦿 New Cyberattack From Winter Vivern Exploits a Zero-Day Vulnerability in Roundcube Webmail 🦿

After reading the technical details about this zero-day that targeted governmental entities and a think tank in Europe and learning about the Winter Vivern threat actor, get tips on mitigating this cybersecurity attack.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Understand the True Cost of a UEM Before Making the Switch πŸ•΄

When investing in a unified endpoint management solution, prioritize the needs of your network and users ahead of brand names. This Tech Tip focuses on questions to ask.

πŸ“– Read

via "Dark Reading".
🦿 TunnelBear VPN Review 2023: Pricing, Ease of Use & Security 🦿

Read our in-depth analysis of TunnelBear VPN, covering its pricing, ease of use, security features, and more. Find out if this is the right VPN for you.

πŸ“– Read

via "Tech Republic".
🦿 5 Best Chrome VPN Extensions for 2023: Complete Buyer’s Guide 🦿

Looking for the best VPNs for Chrome extension to enhance your online security and privacy? Dive into our list of top rated VPNs and find your best fit.

πŸ“– Read

via "Tech Republic".
🦿 The Top 6 Enterprise VPN Solutions to Use in 2023 🦿

Enterprise VPNs are critical for connecting remote workers to company resources via reliable and secure links to foster communication and productivity. Read about six viable choices for businesses.

πŸ“– Read

via "Tech Republic".
🦿 Apple Vulnerability Can Expose iOS and macOS History and Passwords 🦿

This Safari vulnerability has not been exploited in the wild. Apple offers a mitigation, but the fix needs to be enabled manually.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Octo Tempest Group Threatens Physical Violence as Social Engineering Tactic πŸ•΄

The financially motivated English-speaking threat actors use advanced social engineering techniques, SIM swapping, and even threats of violence to breach targets.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5826 β€Ό

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/list_onlineuser.php. The manipulation of the argument SessionId leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243716. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5827 β€Ό

A vulnerability was found in Shanghai CTI Navigation CTI Monitoring and Early Warning System 2.2. It has been classified as critical. This affects an unknown part of the file /Web/SysManage/UserEdit.aspx. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-243717 was assigned to this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46246 β€Ό

Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which is freed in the file `src/ex_docmd.c` in the function `do_cmdline` at line 1010 and then used again in `src/cmdhist.c` at line 759. When using the `:history` command, it's possible that the provided argument overflows the accepted value. Causing an Integer Overflow and potentially later an use-after-free. This vulnerability has been patched in version 9.0.2068.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-27854 β€Ό

An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow. Γ‚ The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product. Γ‚ The user would need to open a malicious file provided to them by the attacker for the code to execute.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46289 β€Ό

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

πŸ“– Read

via "National Vulnerability Database".