πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-11070

An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11069

An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11068

An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11067

An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to hang.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11066

An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11065

An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up messages to users or change a post's appearance.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11064

An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11063

An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11062

An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9548

An issue was discovered in Mattermost Server before 1.2.0. It allows attackers to cause a denial of service (memory consumption) via a small compressed file that has a large size when uncompressed.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 16 stories of the week ⚠

Get yourself up to date with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
πŸ•΄ Cloud Threats and Priorities as We Head Into the Second Half of 2020 πŸ•΄

With millions working from home and relying on the cloud, security leaders are under increasing pressure to keep their enterprises breach-free.

πŸ“– Read

via "Dark Reading: ".
⚠ Hacker indicted for stealing 65K employees’ PII in medical center hack ⚠

The Detroit man allegedly bragged about wanting to "play with Peoplesoft" - the HR management software he called "basically HR in a box."

πŸ“– Read

via "Naked Security".
πŸ•΄ Long-Term Effects of COVID-19 on the Cybersecurity Industry πŸ•΄

The maelstrom of change we're going through presents a unique opportunity to become enablers. And to do that requires flexibility.

πŸ“– Read

via "Dark Reading: ".
πŸ” Employees new to working remotely are a security risk πŸ”

A workforce that was rushed out of the office due to COVID-19 equates to opportunities for cybercriminals, an IBM report finds.

πŸ“– Read

via "Security on TechRepublic".
❌ AMD: Fixes For High-Severity SMM Callout Flaws Upcoming ❌

AMD has fixed one high-severity vulnerability affecting its client and embedded processors; fixes for the other two will come out later in June.

πŸ“– Read

via "Threatpost".
⚠ Anatomy of a survey scam – how innocent questions can rip you off ⚠

We take part in a fraudulent survey so you don't have to. Show your friends and family how these scams unfold.

πŸ“– Read

via "Naked Security".
πŸ” Visa unveils AI tool to help stop digital identity fraud πŸ”

Billions of people have had their information stolen online, and Visa is hoping its new AI solution will help banks handle fraudulent accounts.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Phishing attacks impersonate QuickBooks invoices ahead of July 15 tax deadline πŸ”

Targeting the CEO and others in an organization, the attacks spotted by cybersecurity firm Darktrace were detected due to artificial intelligence.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Employees Say They're Working From Home Without Security Guidance πŸ•΄

Working from home is new for many enterprise employees, yet many say they've received little in the way of new training or technology to keep them safe.

πŸ“– Read

via "Dark Reading: ".
πŸ” 296 GB of Data from Police Departments Leaked Online πŸ”

An activist group posted nearly 300 gigabytes of data from police departments, including scanned documents, videos, emails, audio files, and more, online Friday.

πŸ“– Read

via "Subscriber Blog RSS Feed ".