๐Ÿ›ก Cybersecurity & Privacy ๐Ÿ›ก - News
25.1K subscribers
88.4K links
๐Ÿ—ž The finest daily news on cybersecurity and privacy.

๐Ÿ”” Daily releases.

๐Ÿ’ป Is your online life secure?

๐Ÿ“ฉ lalilolalo.dev@gmail.com
Download Telegram
๐Ÿ•ด Okta Customer Support Breach Exposed Data on 134 Companies ๐Ÿ•ด

1Password, BeyondTrust, and Cloudflare were among five customers directly targeted with stolen Okta session tokens, the company's CSO says.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿฆฟ EleKtra-Leak Campaign Uses AWS Cloud Keys Found on Public GitHub Repositories to Run Cryptomining Operation ๐Ÿฆฟ

In the active Elektra-Leak campaign, attackers hunt for Amazon IAM credentials within public GitHub repositories before using them for cryptomining. Get tips on mitigating this cybersecurity threat.

๐Ÿ“– Read

via "Tech Republic".
๐Ÿ”ฅ1
โ€ผ CVE-2023-3893 โ€ผ

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.

๐Ÿ“– Read

via "National Vulnerability Database".
๐Ÿ•ด Ace Hardware Still Reeling From Weeklong Cyberattack ๐Ÿ•ด

Cyberattackers downed a quarter of the hardware giant's entire IT apparatus. Now, before the company can recover, they're going after individual branches.

๐Ÿ“– Read

via "Dark Reading".
๐Ÿ•ด Critical Atlassian Bug Exploit Now Available; Immediate Patching Needed ๐Ÿ•ด

In-the-wild exploit activity from dozens of cyberattacker networks is ramping up for the security vulnerability in Confluence, tracked as CVE-2023-22518.

๐Ÿ“– Read

via "Dark Reading".
โ€ผ CVE-2022-43555 โ€ผ

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-43554 โ€ผ

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-47235 โ€ผ

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-44569 โ€ผ

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-47233 โ€ผ

The brcm80211 component in the Linux kernel through 6.5.10 has a brcmf_cfg80211_detach use-after-free in the device unplugging (disconnect the USB by hotplug) code. For physically proximate attackers with local access, this "could be exploited in a real world scenario." This is related to brcmf_cfg80211_escan_timeout_worker in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-47234 โ€ผ

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when processing a crafted BGP UPDATE message with a MP_UNREACH_NLRI attribute and additional NLRI data (that lacks mandatory path attributes).

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41725 โ€ผ

Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-41726 โ€ผ

Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2022-3172 โ€ผ

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-36677 โ€ผ

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-45189 โ€ผ

A vulnerability in IBM Robotic Process Automation and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.10, 23.0.0 through 23.0.10 may result in access to client vault credentials. This difficult to exploit vulnerability could allow a low privileged attacker to programmatically access client vault credentials. IBM X-Force ID: 268752.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-35910 โ€ผ

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nucleus_genius Quasar form free รขโ‚ฌโ€œ Contact Form Builder for WordPress allows SQL Injection.This issue affects Quasar form free รขโ‚ฌโ€œ Contact Form Builder for WordPress: from n/a through 6.0.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46381 โ€ผ

LOYTEC LINX-212 firmware 6.2.4 and LVIS-3ME12-A1 firmware 6.2.2 and LIOB-586 firmware 6.2.3 devices lack authentication for the preinstalled version of LWEB-802 via an lweb802_pre/ URI. An unauthenticated attacker can edit any project (or create a new project) and control its GUI.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46380 โ€ผ

LOYTEC LINX-212 firmware 6.2.4 and LVIS-3ME12-A1 firmware 6.2.2 and LIOB-586 firmware 6.2.3 devices send password-change requests via cleartext HTTP.

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-40922 โ€ผ

kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().

๐Ÿ“– Read

via "National Vulnerability Database".
โ€ผ CVE-2023-46382 โ€ผ

LOYTEC LINX-212 firmware 6.2.4 and LVIS-3ME12-A1 firmware 6.2.2 and LIOB-586 firmware 6.2.3 devices use cleartext HTTP for login.

๐Ÿ“– Read

via "National Vulnerability Database".