πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2019-11843

The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18625

Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18624

Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-18623

Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.

πŸ“– Read

via "National Vulnerability Database".
πŸ” NSA Warns of Exim Flaw Being Exploited by Russian Actors πŸ”

In an advisory last week, the NSA warned that a flaw in the Exim mail transfer agent (MTA) has been exploited by Russian cyber military actors since last August.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Amtrak Breach Rolls Over Frequent Travelers πŸ•΄

The breach exposed usernames and passwords of an undisclosed number of program members.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Companies Fall Short on Mandatory Reporting of Cybercrimes πŸ•΄

Understaffed and under fire, companies fail to report cybercrimes even when they are legally obligated to notify authorities, results of a new survey show.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mobile Phishing Attacks Increase Sharply πŸ•΄

Organizations need to include smartphones and tablets in their phishing mitigation strategies, a new report suggests.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 10 Tips for Maintaining Information Security During Layoffs πŸ•΄

Insider cyber threats are always an issue during layoffs -- but with record numbers of home office workers heading for the unemployment line, it's never been harder to maintain cybersecurity during offboarding.

πŸ“– Read

via "Dark Reading: ".
❌ Joomla Resources Directory Users Exposed in Leaky AWS Bucket ❌

Full backup copies of website, including all user data, was exposed for 2,700 JRD users.

πŸ“– Read

via "Threatpost".
⚠ We won! Naked Security scoops β€œLegends of security” award ⚠

We're absolutely delighted - delighted and proud! - to report that we won not one but two awards at last night's European Security Blogger Awards 2020.

πŸ“– Read

via "Naked Security".
πŸ” Return to work: Three tech jobs that companies will be trying to fill πŸ”

Cybersecurity, remote IT troubleshooting and cloud support will be the most sought-after skills for businesses in the months following the COVID-19 pandemic, according to a survey of CIOs and tech executives.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Report: Working from home jeopardizes network security πŸ”

Here's how employees in the US, UK, France and Germany are putting systems at risk, according to CyberArk.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Data breaches cost US companies more than $1.2 trillion last year πŸ”

Unauthorized access was the most common type of attack in 2019, and it was responsible for 40% of all data breaches, says ForgeRock.

πŸ“– Read

via "Security on TechRepublic".
❌ Enterprise Mobile Phishing Attacks Skyrocket Amidst Pandemic ❌

Increase of 37 percent from Q4 2019 to Q1 2020 attributed to creation of remote workforce due to COVID-19 stay-at-home orders.

πŸ“– Read

via "Threatpost".
πŸ•΄ Social Distancing for Healthcare's IoT Devices πŸ•΄

Security pros need to double down around prevention of lateral movement by attackers, especially if IoT devices are connected to the network.

πŸ“– Read

via "Dark Reading: ".
⚠ Amtrak breached, some customers’ logins and PII potentially exposed ⚠

The US rail service hasn't disclosed the number of passengers affected in a 16 April breach.

πŸ“– Read

via "Naked Security".
⚠ VMware flaw allows takeover of multiple private clouds ⚠

VMWare’s VMware Cloud Director has a security flaw that researchers believe could be exploited to compromise multiple customer accounts using the same cloud infrastructure.

πŸ“– Read

via "Naked Security".
πŸ” How to restrict the Nextcloud ONLYOFFICE to groups πŸ”

If you're the Nextcloud admin for your company or home office, you might want to restrict who has access to the ONLYOFFICE suite of tools. Jack Wallen shows you how.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Many Exchange Servers Are Still Vulnerable to Remote Exploit πŸ•΄

A privilege-escalation vulnerability patched in February by Microsoft continues to affect Exchange servers, with more than 80% of Internet-connected servers remaining vulnerable, one firm reports.

πŸ“– Read

via "Dark Reading: ".
❌ Critical SAP ASE Flaws Allow Complete Control of Databases ❌

Researchers warn of critical flaws in SAP's Sybase Adaptive Server Enterprise software.

πŸ“– Read

via "Threatpost".