Security Affairs newsletter Round 418 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37985 | Windows Graphics Component Information Disclosure Vulnerability Windows Graphics Component Information Disclosure Vulnerability NVD description · AI analysis pending | 5.5 | 39% |
| — | ||
| CVE-2023-29489 | An issue was discovered in cPanel before 11.109.9999.116. An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31. NVD description · AI analysis pending | 6.1 | 66% | PoC |
| — |
Full article756 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
May 06, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
We are in the final!
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini
Please nominate Security Affairs as your favorite blog.
Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press
Bitmarck, one of Germany’s largest IT providers, hit by cyberattack
T-Mobile discloses second data breach since the start of 2023
288 dark web vendors arrested in major marketplace seizure
FBI disrupts virtual currency exchanges used to facilitate criminal activity
Cybercriminal Network Fueling the Global Stolen Credit Card Trade is Dismantled
City of Dallas impacted by ransomware attack, police computer dispatch system down
Z-Library eBook site disrupted again by FBI domain seizures
Hacking
Thales seizes control of esa demonstration satellite in first cybersecurity exercise of its kind
TBK DVR Authentication Bypass Attack
Finding XSS in a million websites (cPanel CVE-2023-29489)
ViperSoftX Updates Encryption, Steals Data
Lookout Discovers Android Spyware Tied to Iranian Police Targeting Minorities: BouldSpy
Dog Hunt: Finding Decoy Dog Toolkit via Anomalous DNS Traffic
Elastic Security Labs discovers the LOBSHOT malware
Meta says ChatGPT-related malware is on the rise
The malware threat landscape: NodeStealer, DuckTail, and more
Not quite an Easter egg: a new family of Trojan subscribers on Google Play
Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign
Intelligence and Information Warfare
APT28 cyberattack: distribution of emails with “instructions” on “updating the operating system”
Nomadic Octopus’ Paperbug Campaign
CHAIN REACTION: ROKRAT’S MISSING LINK
Pro-Russian Hackers Claim Downing of French Senate Website
Cybersecurity
How we fought bad apps and bad actors in 2022
So long passwords, thanks for all the phish
Three New BGP Message Parsing Vulnerabilities Disclosed in FRRouting Software
Twitter admits to ‘security incident’ involving Circles tweets
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/145871/breaking-news/security-affairs-newsletter-round-418.html