πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.1K subscribers
88.5K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-42632 β€Ό

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-48455 β€Ό

In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42637 β€Ό

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42651 β€Ό

In engineermode, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42631 β€Ό

In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-42646 β€Ό

In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Unsolved Cyber Mysteries: Signal Hacking πŸ•΄

Episode 1 of Bugcrowd’’s docuseries, Unsolved Cyber Mysteries, describes signal hacking attacks in the 1980s and the potential motivations behind them.

πŸ“– Read

via "Dark Reading".
🦿 Australian CEOs Struggling to Face Cyber Risk Realities 🦿

Research has found 91% of CEOs view IT security as a technical function that's the CIO or CISO's problem, meaning IT leaders have more work to do to engage senior executives and boards.

πŸ“– Read

via "Tech Republic".
πŸ•΄ It's Cheap to Exploit Software β€” and That's a Major Security Problem πŸ•΄

The solution? Follow in the footsteps of companies that have raised the cost of exploitation.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2023-5625 β€Ό

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-4452 β€Ό

A vulnerability has been identified in the EDR-810, EDR-G902, and EDR-G903 Series, making them vulnerable to the denial-of-service vulnerability. This vulnerability stems from insufficient input validation in the URI, potentially enabling malicious users to trigger the device reboot.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46930 β€Ό

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46927 β€Ό

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46931 β€Ό

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-46928 β€Ό

GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 3 Ways to Close the Cybersecurity Skills Gap β€” Now πŸ•΄

The future of the cybersecurity workforce will rely less on long-led legacy education models and more on skills-now training.

πŸ“– Read

via "Dark Reading".
πŸ•΄ FBI Director Warns of Increased Iranian Attacks πŸ•΄

Christopher Wray tells the US Senate that more US infrastructure will be targeted for cyberattacks in the wake of the Gaza conflict.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Atlassian Customers Should Patch Latest Critical Vuln Immediately πŸ•΄

Atlassian CISO warns Confluence Data Center and Server customers they're vulnerable to "significant data loss" if all on-premises versions aren't patched.

πŸ“– Read

via "Dark Reading".
🦿 Amazon Web Services Launches Independent European Cloud as Calls for Data Sovereignty Grow 🦿

The AWS Sovereign Cloud will be physically and logically separate from other AWS clouds and has been designed to comply with Europe's stringent data laws.

πŸ“– Read

via "Tech Republic".
🦿 4 Best Small Business VPNs for 2023 🦿

Looking for the best VPN services for SMBs? Here's a comprehensive guide covering the top options for secure remote access and data protection on a budget.

πŸ“– Read

via "Tech Republic".
πŸ‘Ž1
β€Ό CVE-2023-20195 β€Ό

Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilities are due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit these vulnerabilities by uploading a crafted file to an affected device. A successful exploit could allow the attacker to store malicious files in specific directories on the device. The attacker could later use those files to conduct additional attacks, including executing arbitrary code on the affected device with root privileges.

πŸ“– Read

via "National Vulnerability Database".