โ Fresh phish! Stripe scam baked and delivered in under an hour โ
๐ Read
via "Naked Security".
Less than an hour after the crooks registered their scamming domain, the phishing attack was under way.๐ Read
via "Naked Security".
Naked Security
Fresh phish! Stripe scam baked and delivered in under an hour
Less than an hour after the crooks registered their scamming domain, the phishing attack was under way.
โ Ironpie robot vacuum can suck up your privacy โ
๐ Read
via "Naked Security".
You might want to unplug this not-so-smart robot: researchers found they can watch video streams piped out from its security camera.๐ Read
via "Naked Security".
Naked Security
Ironpie robot vacuum can suck up your privacy
You might want to unplug this not-so-smart robot: researchers found they can watch video streams piped out from its security camera.
โ Letโs Encrypt issues one billionth free certificate โ
๐ Read
via "Naked Security".
Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago.๐ Read
via "Naked Security".
Naked Security
Letโs Encrypt issues one billionth free certificate
Thanks to this flood of free certificates, the web is a lot more encrypted than it was a few years ago.
๐ด What Disney+ Can Teach Businesses About Customer Security ๐ด
๐ Read
via "Dark Reading: ".
Businesses must prioritize customer protection by taking on some of the responsibility to prevent credential stuffing attacks through multipronged authentication and identity management.๐ Read
via "Dark Reading: ".
Dark Reading
What Disney+ Can Teach Businesses About Customer Security - Dark Reading
Businesses must prioritize customer protection by taking on some of the responsibility to prevent credential stuffing attacks through multipronged authentication and identity management.
ATENTIONโผ New - CVE-2018-17058
๐ Read
via "National Vulnerability Database".
An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/<number>/<filename>. Accessing the file once uploaded does not require authentication.๐ Read
via "National Vulnerability Database".
โ Walgreens Mobile App Leaks Prescription Data โ
๐ Read
via "Threatpost".
A security error in the Walgreens mobile app may have leaked customers' full names, prescriptions and shipping addresses.๐ Read
via "Threatpost".
Threat Post
Walgreens Mobile App Leaks Prescription Data
A security error in the Walgreens mobile app may have leaked customers' full names, prescriptions and shipping addresses.
๐ด Name That Toon: Holy Cow! ๐ด
๐ Read
via "Dark Reading: ".
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.๐ Read
via "Dark Reading: ".
Dark Reading
Name That Toon: Holy Cow!
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.
๐ Morphisec is using the Windows 10 transition to help companies boost security ๐
๐ Read
via "Security on TechRepublic".
Morphisec combines the anti-virus protection in the new Microsoft OS with its own defenses against malware.๐ Read
via "Security on TechRepublic".
TechRepublic
Morphisec is using the Windows 10 transition to help companies boost security
Morphisec combines the anti-virus protection in the new Microsoft OS with its own defenses against malware.
โ TrickBot Adds ActiveX Control, Hides Dropper in Images โ
๐ Read
via "Threatpost".
The tricky trojan has evolved again, to stay a step ahead of defenders.๐ Read
via "Threatpost".
Threat Post
TrickBot Adds ActiveX Control, Hides Dropper in Images
The tricky trojan has evolved again, to stay a step ahead of defenders.
๐ด Tesla, SpaceX Parts Manufacturer Suffers Data Breach ๐ด
๐ Read
via "Dark Reading: ".
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.๐ Read
via "Dark Reading: ".
Darkreading
Tesla, SpaceX Parts Manufacturer Suffers Data Breach
Visser Precision has confirmed a security incident likely caused by the data-stealing DoppelPaymer ransomware.
ATENTIONโผ New - CVE-2019-12183
๐ Read
via "National Vulnerability Database".
Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the administrative API.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2017-12580
๐ Read
via "National Vulnerability Database".
An issue was discovered in IDM UltraEdit through 24.10.0.32. To exploit the vulnerability, on unpatched Windows systems, an attacker could include in the same directory as the affected executable a DLL using the name of a Windows DLL. This DLL must be preloaded by the executable (for example, "ntmarta.dll"). When the installer EXE is executed by the user, the DLL located in the EXE's current directory will be loaded instead of the Windows DLL, allowing the attacker to run arbitrary code on the affected system.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2015-1583
๐ Read
via "National Vulnerability Database".
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account via a request to mods/_core/users/admins/create.php or (2) create a user account via a request to mods/_core/users/create_user.php.๐ Read
via "National Vulnerability Database".
โ RSAC: Keeping Smart Cities Safe From Hacks โ
๐ Read
via "Threatpost".
As cities grow more connected, municipal operators must deal with new risks like ransomware, IoT hacks and more.๐ Read
via "Threatpost".
Threat Post
Forrester: Keeping Smart Cities Safe From Hacks
As cities grow more connected, municipal operators must deal with new risks like ransomware, IoT hacks and more.
๐ Companies Increasingly Complacent Around Data Breach Preparedness ๐
๐ Read
via "Subscriber Blog RSS Feed ".
Ponemon Institute's annual data breach readiness survey suggests the increased adoption of security technologies but the continuation of problems, like spear phishing attacks.๐ Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Companies Increasingly Complacent Around Data Breach Preparedness
Ponemon Institute's annual data breach readiness survey suggests the increased adoption of security technologies but the continuation of problems, like spear phishing attacks.
ATENTIONโผ New - CVE-2019-14892
๐ Read
via "National Vulnerability Database".
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-14384
๐ Read
via "National Vulnerability Database".
The Website Manager module in SEO Panel 3.13.0 and earlier is affected by a stored Cross-Site Scripting (XSS) vulnerability, allowing remote authenticated attackers to inject arbitrary web script or HTML via the websites.php name parameter.๐ Read
via "National Vulnerability Database".
ATENTIONโผ New - CVE-2018-11675
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.๐ Read
via "National Vulnerability Database".
๐ Report: Coronavirus is negatively impacting international call quality ๐
๐ Read
via "Security on TechRepublic".
When entire regions are quarantined, home-bound people are overloading local switches, reducing international call quality and interrupting connectivity.๐ Read
via "Security on TechRepublic".
TechRepublic
Coronavirus is negatively impacting international call quality
When entire regions are quarantined, home-bound people are overloading local switches, reducing international call quality and interrupting connectivity.
๐ด Walgreens' Mobile App Exposes Customers' Info ๐ด
๐ Read
via "Dark Reading: ".
An error in the app allowed some secure chat users to see medical information that wasn't theirs.๐ Read
via "Dark Reading: ".
Darkreading
Walgreens' Mobile App Exposes Customers' Info
An error in the app allowed some secure chat users to see medical information that wasn't theirs.