πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-19516

messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-10704

yidashi yii2cmf 2.0 has XSS via the /search q parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18350

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-3641

bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crash) via an "Easy" attack.

πŸ“– Read

via "National Vulnerability Database".
⚠ Confessions app Whisper spills almost a billion records ⚠

Researchers say the exposure includes exact locations of users' last posts, nicknames, age, and gender.

πŸ“– Read

via "Naked Security".
⚠ Homeland Security sued over secretive use of face recognition ⚠

As of June 2019, CBP had processed more than 20 million travelers using facial recognition, civil rights group ACLU says.

πŸ“– Read

via "Naked Security".
⚠ EARN IT Act threatens end-to-end encryption ⚠

The bill, which would undercut Section 230 protections for online publishing, presents itself as a way to stop online child abuse.

πŸ“– Read

via "Naked Security".
πŸ” Dang... How Did I Miss International Women’s Day on Sunday, March 8?! πŸ”

While there have been some successes when it comes to getting women involved in tech, by and large, we haven't made enough progress.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ ACLU Sues Over U.S. Airport Facial-Recognition Technology ❌

Civil-liberties group wants more transparency about who the government is partnering with and how they are using the information gathered in biometric checks.

πŸ“– Read

via "Threatpost".
πŸ•΄ A Lesson in Social Engineering πŸ•΄

What kind of school project is this?

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2009-5159

Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Princess Cruises Confirms Data Breach πŸ•΄

The cruise liner, forced to shut down operations due to coronavirus, says the incident may have compromised passengers' personal data.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ What Cybersecurity Pros Really Think About Artificial Intelligence πŸ•΄

While there's a ton of unbounded optimism from vendor marketing and consultant types, practitioners are still reserving a lot of judgment.

πŸ“– Read

via "Dark Reading: ".
❌ Coronavirus-Themed APT Attack Spreads Malware ❌

The APT group was spotted sending spear-phishing emails that purport to detail information about coronavirus - but they actually infect victims with a custom RAT.

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 3/13 πŸ”

Ryuk Ransomware targets another U.S. city, University of Kentucky ends a month-long cyberattack, and a secret-sharing app exposes user data - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Beyond Burnout: What Is Cybersecurity Doing to Us? πŸ•΄

Infosec professionals may feel not only fatigued, but isolated, unwell, and unsafe. And the problem may hurt both them and the businesses they aim to protect.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Big BEC Bust Brings Down Dozens πŸ•΄

Two dozen individuals have been named in the latest arrests of alleged participants in a business email compromise scheme that cost victims $30 million.

πŸ“– Read

via "Dark Reading: ".
❌ WordPress Plugin Bug in Popup Builder Threatens 100K Websites ❌

The high-severity flaw allows malicious code injection into website pop-up windows.

πŸ“– Read

via "Threatpost".
❌ Working from Home: COVID-19’s Constellation of Security Challenges ❌

Organizations are sending employees and students home to work and learn -- but implementing the plan opens the door to more attacks, IT headaches and brand-new security challenges.

πŸ“– Read

via "Threatpost".