πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ The Bright Side of the Dark Web πŸ•΄

As the hitmen and fraudsters retreat, the Dark Web could become freedom's most important ally.

πŸ“– Read

via "Dark Reading: ".
πŸ” Exposing the dark web coronavirus scammers πŸ”

Kurtis Minder, co-founder and CEO of GroupSense, explains why the coronavirus has been big business for bad actors.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Exposing the dark web coronavirus scammers πŸ”

Kurtis Minder, co-founder and CEO of GroupSense, explains why the coronavirus has been big business for bad actors.

πŸ“– Read

via "Security on TechRepublic".
❌ β€˜Lamphone’ Hack Uses Lightbulb Vibrations to Eavesdrop on Homes ❌

A new hack allowed researchers to discern sound -- including "Let it Be" by the Beatles, and audio from a Donald Trump speech -- from lightbulb vibrations.

πŸ“– Read

via "Threatpost".
❌ Claire’s Customers Targeted with Magecart Payment-Card Skimmer ❌

The Magecart group targeted the tween accessories specialist starting the day after it shuttered its retail locations due to coronavirus.

πŸ“– Read

via "Threatpost".
⚠ Congress wants to know who is using spyware against the US ⚠

A 2021 intelligence funding draft bill mandates a report on surveillance vendors and which countries or other actors are using spyware.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2019-19112

The wpForo plugin 1.6.5 for WordPress allows XSS involving the wpf-dw-td-value class of dashboard.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19111

The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases langid parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19110

The wpForo plugin 1.6.5 for WordPress allows XSS via the wp-admin/admin.php?page=wpforo-phrases s parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19109

The wpForo plugin 1.6.5 for WordPress allows wp-admin/admin.php?page=wpforo-usergroups CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-16848

A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18869

A TOCTOU issue in the chownr package before 1.1.0 for Node.js 10.10 could allow a local attacker to trick it into descending into unintended directories via symlink attacks.

πŸ“– Read

via "National Vulnerability Database".
⚠ You’ve heard of sextortion – now there’s β€œbreachstortion”, too.. ⚠

Sextortion again - but with "we hacked your website and stole all your data" instead of "we hacked your webcam and made a video".

πŸ“– Read

via "Naked Security".
πŸ•΄ Microsoft Releases Update for DoS Flaw in .NET Core πŸ•΄

Customers are advised to install the latest version of PowerShell to fully address CVE-2020-1108.

πŸ“– Read

via "Dark Reading: ".
πŸ” Top 5 things to know about security breaches πŸ”

Verizon's annual Data Breach Investigations Report confirmed 3,950 data breaches across 16 industries. Tom Merritt explains five things to know about these breaches.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 things to know about security breaches πŸ”

Verizon's annual Data Breach Investigations Report confirmed 3,950 data breaches across 16 industries. Tom Merritt explains five things to know about these breaches.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2019-20838

libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21246

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21245

Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

πŸ“– Read

via "National Vulnerability Database".
❌ WFH Alert: Critical Bug Found in Old D-Link Router Models ❌

Researchers find six bugs in consumer D-Link DIR-865L Wireless AC 1750 Dual Band Cloud Router.

πŸ“– Read

via "Threatpost".
❌ Intel Adds Anti-Malware Protection in Tiger Lake CPUs ❌

Intel's Tiger Lake CPUs will come with Control-flow Enforcement Technology (CET), aimed at battling common control-flow hijacking attacks.

πŸ“– Read

via "Threatpost".