Security
Headlines
HeadlinesLatestCVEs

Tag

#ios

Red Hat Security Advisory 2023-2097-03

Red Hat Security Advisory 2023-2097-03 - Red Hat Satellite is a systems management tool for Linux-based infrastructure. It allows for provisioning, remote management, and monitoring of multiple Linux deployments with a single centralized tool. Issues addressed include code execution, cross site scripting, denial of service, deserialization, improper neutralization, information leakage, and remote shell upload vulnerabilities.

Packet Storm
#sql#xss#vulnerability#web#ios#mac#google#linux#debian#red_hat#ddos#dos#apache#redis#js#git#java#rce#perl#ldap#vmware#acer#oauth#auth#ssh#ruby#rpm#postgres#docker#sap#ssl
World Password Day must die

Categories: News Critical technology should not require an annual pep talk to function correctly. (Read more...) The post World Password Day must die appeared first on Malwarebytes Labs.

CVE-2023-22640: Fortiguard

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, FortiOS version 6.2.0 through 6.2.13, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.1, FortiProxy version 7.0.0 through 7.0.7, FortiProxy all versions 2.0, FortiProxy all versions 1.2, FortiProxy all versions 1.1, FortiProxy all versions 1.0 allows an authenticated attacker to execute unauthorized code or commands via specifically crafted requests.

Databricks Platform Cluster Isolation Bypass

The Databricks Platform as of 2023-01-26 suffered from a cluster isolation bypass vulnerability through insecure defaults and shared storage.

Google Authenticator WILL get end-to-end encryption. Eventually.

Categories: News Google has promised to add end-to-end encryption to Google Authenticator backups after users were warned against turning on the new feature. (Read more...) The post Google Authenticator WILL get end-to-end encryption. Eventually. appeared first on Malwarebytes Labs.

Google Is Rolling Out Passkeys, the Password-Killing Tech, to All Accounts

The tech industry’s transition to passkeys gets its first massive boost with the launch of the alternative login scheme for Google’s billions of users.

Apple and Google Join Forces to Stop Unauthorized Tracking Alert System

Apple and Google have teamed up to work on a draft industry-wide specification that's designed to tackle safety risks and alert users when they are being tracked without their knowledge or permission using devices like AirTags. "The first-of-its-kind specification will allow Bluetooth location-tracking devices to be compatible with unauthorized tracking detection and alerts across Android and

GHSA-f8hp-grmr-pp7j: RosarioSIS vulnerable to CSV Injection

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.

CVE-2023-29918: RosarioSIS 10.8.4 - CSV Injection

RosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.