πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Threat Awareness: A Critical First Step in Detecting Adversaries πŸ•΄

One thing seems certain: Attackers are only getting more devious and lethal. Expect to see more advanced attacks.

πŸ“– Read

via "Dark Reading: ".
⚠ One billion Android smartphones racking up security flaws ⚠

How long do Android devices continue to receive security updates after they’re purchased? The answer is: barely two years.

πŸ“– Read

via "Naked Security".
πŸ” Cyberattackers are delivering malware by using links from whitelisted sites πŸ”

Legitimate-looking links from OneDrive, Google Drive, iCloud, and Dropbox slip by standard security measures.

πŸ“– Read

via "Security on TechRepublic".
❌ AMD Downplays CPU Threat Opening Chips to Data Leak Attacks ❌

New side-channel attacks have been disclosed in AMD CPUs, however AMD said that they are not new.

πŸ“– Read

via "Threatpost".
πŸ•΄ WatchGuard Buys Panda Security for Endpoint Security Tech πŸ•΄

In the long term, Panda Security's technologies will be integrated into the WatchGuard platform.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-7968

nwbc_ext2int in SAP NetWeaver Application Server before Security Note 2183189 allows XXE attacks for local file inclusion via the sap/bc/ui2/nwbc/nwbc_ext2int/ URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7344

HikaShop Joomla Component before 2.6.0 has XSS via an injected payload[/caption].

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7343

JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Malware Campaign Feeds on Coronavirus Fears πŸ•΄

A new malware campaign that offers a "coronavirus map" delivers a well-known data-stealer.

πŸ“– Read

via "Dark Reading: ".
πŸ›  Richsploit RichFaces Exploitation Toolkit πŸ› 

This tool can be used to exploit vulnerable versions of RichFaces. It has payloads for 4 vulnerabilities that have been identified, which can lead to remote code execution via java deserialization and EL injection.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
❌ Microsoft Exchange Server Flaw Exploited in APT Attacks ❌

A vulnerability is Microsoft Exchange servers is being actively exploited by multiple APT groups, researchers warn.

πŸ“– Read

via "Threatpost".
⚠ It’s not a breach… it’s just that someone else has your data ⚠

If you lose someone's data because of a configuration blunder that lets crooks in without any actual hacking... is that a "breach" or not?

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2016-6918

Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-1159

In ZOHO Password Manager Pro (PMP) 8.3.0 (Build 8303) and 8.4.0 (Build 8400,8401,8402), underprivileged users can obtain sensitive information (entry password history) via a vulnerable hidden service.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7342

JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cyber Resiliency, Cloud & the Evolving Role of the Firewall πŸ•΄

Today's defenses must be creative in both isolating threats and segmenting environments to prevent attacks. Here's why.

πŸ“– Read

via "Dark Reading: ".
πŸ” Federal Employees Worked to Defraud Govt Through Stolen Data πŸ”

A one-time inspector general at the Department of Homeland Security was indicted on Friday on charges he conspired to steal the U.S. government's proprietary software and databases.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2015-7341

JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7340

JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7339

JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-7338

SQL Injection exists in AcyMailing Joomla Component before 4.9.5 via exportgeolocorder in a geolocation_longitude request to index.php.

πŸ“– Read

via "National Vulnerability Database".