Cross Site Request Forgery vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via the system/user/save parameter.
Monthly Archives: April 2023
CVE-2020-19277
Cross Site Scripting vulnerability found in Phachon mm-wiki v.0.1.2 allows a remote attacker to execute arbitrary code via javascript code in the markdown editor.
pdns-recursor-4.8.4-1.el8
FEDORA-EPEL-2023-d4a7c0e04e
Packages in this update:
pdns-recursor-4.8.4-1.el8
Update description:
Update to 4.8.4
Release notes: https://doc.powerdns.com/recursor/changelog/4.8.html
North Korea Hacking Cryptocurrency Sites with 3CX Exploit
News:
Researchers at Russian cybersecurity firm Kaspersky today revealed that they identified a small number of cryptocurrency-focused firms as at least some of the victims of the 3CX software supply-chain attack that’s unfolded over the past week. Kaspersky declined to name any of those victim companies, but it notes that they’re based in “western Asia.”
Security firms CrowdStrike and SentinelOne last week pinned the operation on North Korean hackers, who compromised 3CX installer software that’s used by 600,000 organizations worldwide, according to the vendor. Despite the potentially massive breadth of that attack, which SentinelOne dubbed “Smooth Operator,” Kaspersky has now found that the hackers combed through the victims infected with its corrupted software to ultimately target fewer than 10 machines—at least as far as Kaspersky could observe so far—and that they seemed to be focusing on cryptocurrency firms with “surgical precision.”
TikTok Fined £12.7m For Violating UK Data Privacy Laws
The ICO said TikTok failed to provide proper information on how data is collected, used and shared
TrustCloud releases TrustRegister to help gauge business impact of risks
Trust assurance platform TrustCloud has announced the release of the TrustRegister application to help software companies identify risks and understand risk-related revenue/business impact. TrustRegister is the newest addition to the TrustCloud platform and is built to automatically assign, notify, and prioritize tasks and remediation plans to help businesses elevate governance, risk management, and compliance (GRC) processes in line with frameworks such as SOC 2 and ISO 27001, the vendor said. The release comes as organizations and GRC teams face significant challenges amid the ongoing advancement of technology, changing regulations, and the increased interconnection of enterprises.
USN-5996-1: Liblouis vulnerabilities
It was discovered that Liblouis incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-26767, CVE-2023-26768, CVE-2023-26769)
pdns-recursor-4.8.4-1.el9
FEDORA-EPEL-2023-bb6f0bba09
Packages in this update:
pdns-recursor-4.8.4-1.el9
Update description:
Update to 4.8.4
Release notes: https://doc.powerdns.com/recursor/changelog/4.8.html
pdns-recursor-4.8.4-1.fc38
FEDORA-2023-680b2e6af5
Packages in this update:
pdns-recursor-4.8.4-1.fc38
Update description:
Update to 4.8.4
Release notes: https://doc.powerdns.com/recursor/changelog/4.8.html
pdns-recursor-4.8.4-1.fc37
FEDORA-2023-0c1aaa76b6
Packages in this update:
pdns-recursor-4.8.4-1.fc37
Update description:
Update to 4.8.4
Release notes: https://doc.powerdns.com/recursor/changelog/4.8.html