πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Instagram Retained Deleted User Data Despite GDPR Rules ❌

The photo-sharing app retained people’s photos and private direct messages on its servers even after users removed them.

πŸ“– Read

via "Threatpost".
πŸ•΄ WFH Summer 2020 Caption Contest Winners πŸ•΄

Clever wordplay on sandcastles, sandboxes, zero trust. and granular controls. And the winners are ...

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 7 Ways to Keep Your Remote Workforce Safe πŸ•΄

These tips will help you chart a course for a security strategy that just may become part of the normal way organizations will function over the next several years.

πŸ“– Read

via "Dark Reading: ".
πŸ” How cybercriminals are exploiting US unemployment benefits to make money πŸ”

Scammers use Social Security numbers and other data to create synthetic IDs to collect unemployment benefits, says IntSights.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Friday Five: 8/14 Edition πŸ”

Ransomware group launches a new data leak site, 1 Billion Android phones possibly at risk of data theft, and England is testing a new coronavirus contact-tracing app - catch up on the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2019-7410

There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web script or HTML via $page_title in /lib/Galileo/files/templates/page/show.html.ep (aka the PAGE TITLE Field).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-6112

A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the keyword parameter (aka $search_term or the Search field).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-19643

ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Forcepoint Hopes for Breakout Moment by Hopping on the ZTA Bandwagon πŸ•΄

The debut of Forcepoint's two-pronged zero trust access (ZTA) solution delivers much-needed competitive momentum, but it must do more to stand out against a growing field of ZTA competitors.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-5591

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Flaws in WordPress Quiz Plugin Allow Site Takeover ❌

The recently patched flaws could be abused by an unauthenticated, remote attackers to take over vulnerable websites.

πŸ“– Read

via "Threatpost".
πŸ•΄ DHS CISA Warns of Phishing Emails Rigged with KONNI Malware πŸ•΄

Konni is a remote administration tool cyberattackers use to steal files, capture keystrokes, take screenshots, and execute malicious code.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-8033

In Textpattern 4.5.7, the password-reset feature does not securely tether a hash to a user account.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-8032

In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.

πŸ“– Read

via "National Vulnerability Database".
❌ Mac Users Targeted by Spyware Spreading via Xcode Projects ❌

The XCSSET suite of malware also hijacks browsers, has a ransomware module and more -- and uses a pair of zero-day exploits.

πŸ“– Read

via "Threatpost".
πŸ•΄ IcedID Shows Obfuscation Sophistication in New Campaign πŸ•΄

The malware's developers have turned to dynamic link libraries (DLLs) to hide their work.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Research Casts Doubt on Value of Threat Intel Feeds πŸ•΄

Two commercial threat intelligence services and four open source feeds rarely provide the same information, raising questions about how security teams should gauge their utility.

πŸ“– Read

via "Dark Reading: ".
❌ PoC Exploit Targeting Apache Struts Surfaces on GitHub ❌

Researchers have discovered freely available PoC code and exploit that can be used to attack unpatched security holes in Apache Struts 2.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2020-0255

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751. Notes: All CVE users should reference CVE-2020-10751 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-11085

php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant stored XSS, via the question_name parameter because js/admin_question.js mishandles parsing inside of a SCRIPT element.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – catch up on our latest articles and videos ⚠

Our recent articles and videos, all in one place.

πŸ“– Read

via "Naked Security".