Cyber Newsroom Feed
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

-
cert.pl
Vulnerability in Kofax Capture software
CVE ID CVE-2023-5118 Publication date 11 January 2024 Vendor Kofax Product Capture Vulnerable versions through 11.0.0 Vulnerability type (CWE) Stored XSS (CWE-79) Report source Report to CERT Polska D ... Read more

-
cert.pl
Vulnerability in TCExam software
CVE ID CVE-2023-6554 Publication date 11 January 2024 Vendor Tecnick.com Product TCExam Vulnerable versions All below 15.1.0 Vulnerability type (CWE) Missing Authorization (CWE-862) Report source Own ... Read more

-
cert.pl
Vulnerability in PrestaShop Google Integrator software
CVE ID CVE-2023-6921 Publication date 08 January 2024 Vendor PrestaShow Product PrestaShop Google Integrator Vulnerable versions All below 2.1.4 Vulnerability type (CWE) SQL injection (CWE-89) Report ... Read more

-
cert.pl
Vulnerability in TasmoAdmin software
CVE ID CVE-2023-6552 Publication date 08 January 2024 Vendor TasmoAdmin Product TasmoAdmin Vulnerable versions All below 3.3.0 Vulnerability type (CWE) URL Redirection to Untrusted Site (CWE-601) Repo ... Read more

-
cert.pl
Vulnerability in class.upload.php open source library
CVE ID CVE-2023-6551 Publication date 04 January 2024 Vendor Colin Verot Product class.upload.php Vulnerable versions All Vulnerability type (CWE) Improper Input Validation (CWE-20) Report source Own ... Read more

-
cert.pl
Vulnerability in CoolKit Technology eWeLink mobile application (Android & iOS)
CVE ID CVE-2023-6998 Publication date 30 December 2023 Vendor CoolKit Technology Product eWeLink (Android & iOS) Vulnerable versions All below 5.2.0 Vulnerability type (CWE) Improper Privilege Managem ... Read more

-
cert.pl
Vulnerability in MegaBIP and SmodBIP software
CVE ID CVE-2023-5378 Publication date 20 December 2023 Vendor Jan Syski Product SmodBIP and MegaBIP Vulnerable versions SmodBIP: all, MegaBIP: all through 4.36.2 Vulnerability type (CWE) Improper Inpu ... Read more

-
cert.pl
Russian Foreign Intelligence Service (SVR) Cyber Actors Use JetBrains TeamCity CVE in Global Targeting
The Federal Bureau of Investigation (FBI), US Cybersecurity & Infrastructure Security Agency (CISA), National Security Agency (NSA), Polish Military Counterintelligence Service (SKW), CERT Polska (CER ... Read more

-
cert.pl
Vulnerability in SAS 9.4 software
CVE ID CVE-2023-4932 Publication date 12 December 2023 Vendor SAS Institute Product SAS Vulnerable versions 9.4_M7 and 9.4_M8 Vulnerability type (CWE) Reflected XSS (CWE-79) Report source Report to CE ... Read more

-
huntress.com
MFT Exploitation and Adversary Operations | Huntress
Threat actors of varying types continue to target managed file transfer (MFT) applications for exploitation. The latest concerning MFT vulnerability was identified by Converge Technology Solutions, or ... Read more