Bank for International Settlements publishes Project Polaris
Monthly Archives: July 2023
Martin Lewis Shocked at Deepfake Investment Scam Ad
Cyber Extortion Cases Surge 39% Annually
ZDI-23-904: Delta Electronics InfraSuite Device Master APRunning Improper Access Control Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Delta Electronics InfraSuite Device Master. Authentication is required to exploit this vulnerability.
ZDI-23-905: Delta Electronics InfraSuite Device Master modifyusergroup Improper Access Control Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Delta Electronics InfraSuite Device Master. Authentication is required to exploit this vulnerability.
ZDI-23-906: Delta Electronics InfraSuite Device Master Device-Gateway Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics InfraSuite Device Master. Authentication is not required to exploit this vulnerability.
ZDI-23-907: Siemens Solid Edge Viewer DWG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
magicmirror-2.24.0-1.fc39
FEDORA-2023-3a06c965b4
Packages in this update:
magicmirror-2.24.0-1.fc39
Update description:
Automatic update for magicmirror-2.24.0-1.fc39.
Changelog
* Sun Jul 9 2023 Davide Cavalca <dcavalca@fedoraproject.org> – 2.24.0-1
– Update to 2.24.0; Fixes: RHBZ#2184597, RHBZ#2203762, RHBZ#2216895
DSA-5451 thunderbird – security update
Multiple security issues were discovered in Thunderbird, which could
result in denial of service or the execution of arbitrary code.
Multiple Vulnerabilities in Progress MOVEit Transfer Could Allow for Unauthorized Database Access
Multiple vulnerabilities have been discovered in Progress Moveit Transfer, which could allow for unauthorized database access. MOVEit Transfer is a managed file transfer software that allows the enterprise to securely transfer files between business partners and customers using SFTP, SCP, and HTTP-based uploads. If successfully exploited, an attacker could gain unauthorized access to the database, potentially compromising confidential information, user credentials, and other sensitive data. This unauthorized access could also result in unauthorized modifications and disclosure of the database content.