🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 LastPass Hikes Password Requirements to 12 Characters 🕴

A phased rollout will also prompt LastPass customers to re-enroll their accounts in multifactor authentication (MFA) to prevent future breaches.

📖 Read

via "Dark Reading".
🕴 Cybercriminals Flood Dark Web With X (Twitter) Gold Accounts 🕴

Verified accounts for celebs and organizations deliver a deep vein of cybercrime riches for crooks.

📖 Read

via "Dark Reading".
🕴 iFlock Security Consulting Secures Private Funding 🕴



📖 Read

via "Dark Reading".
🕴 SonicWall Accelerates SASE Offerings; Acquires Proven Cloud Security Provider 🕴



📖 Read

via "Dark Reading".
🕴 SentinelOne to Expand Cloud Security Capabilities With Acquisition of PingSafe 🕴



📖 Read

via "Dark Reading".
🕴 Ransomware Group Claims Cyber Breach of Xerox Subsidiary 🕴

After Xerox cybersecurity personnel discovered the breach, they brought in third-party experts to investigate.

📖 Read

via "Dark Reading".
🕴 Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv 🕴

Incident prompts Ukraine's security service to ask webcam operators in country to stop live broadcasts.

📖 Read

via "Dark Reading".
‼️CVE-2023-41776‼️

There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular user privileges can create a fake process, and to escalate local privileges.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41779‼️

There is an illegal memory access vulnerability of ZTE's ZXCLOUD iRAI product.When the vulnerability is exploited by an attacker with the common user permission, the physical machine will be crashed.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41780‼️

There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-41783‼️

There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50345‼️

HCL DRYiCE MyXalytics is impacted by an Open Redirect vulnerability which could allow an attacker to redirect users to malicious sites, potentially leading to phishing attacks or other security threats.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50346‼️

HCL DRYiCE MyXalytics is impacted by an information disclosure vulnerability. Certain endpoints within the application disclose detailed file information.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50348‼️

HCL DRYiCE MyXalytics is impacted by an improper error handling vulnerability. The application returns detailed error messages that can provide an attacker with insight into the application, system, etc.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50350‼️

HCL DRYiCE MyXalytics is impacted by the use of a broken cryptographic algorithm for encryption, potentially giving an attacker ability to decrypt sensitive information.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50351‼️

HCL DRYiCE MyXalytics is impacted by the use of an insecure key rotation mechanism which can allow an attacker to compromise the confidentiality or integrity of data.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-45722‼️

HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-45723‼️

HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path including the file name where these files are stored on the server.

📖 Read more

Via "National Vulnerability Database"
👍1
‼️CVE-2023-45724‼️

HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50341‼️

HCL DRYiCE MyXalytics is impacted by Improper Access Control Obsolete web pages vulnerability. Discovery of outdated and accessible web pages, reflects a "Missing Access Control" vulnerability, which could lead to inadvertent exposure of sensitive information andor exposing a vulnerable endpoint.

📖 Read more

Via "National Vulnerability Database"
‼️CVE-2023-50342‼️

HCL DRYiCE MyXalytics is impacted by an Insecure Direct Object Reference IDOR vulnerability.  A user can obtain certain details about another user as a result of improper access control.

📖 Read more

Via "National Vulnerability Database"