πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Nvidia Warns Windows Gamers on GPU Driver Flaws ❌

Nvidia has patched three vulnerabilities in its Windows GPU display driver that could enable information disclosure, denial of service and privilege escalation.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-12885

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12795

OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-12789

Metinfo 5.3.18 is affected by: Cross Site Request Forgery (CSRF). The impact is: Information Disclosure (remote). The component is: admin/interface/online/delete.php. The attack vector is: The administrator clicks on the malicious link in the login state.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-1006

A vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

πŸ“– Read

via "National Vulnerability Database".
❌ The WannaCry Security Legacy and What’s to Come ❌

The WannaCry attack proved pivotal, changing the way organizations go about securing their environments.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft SharePoint Bug Exploited in the Wild πŸ•΄

A number of reports show CVE-2019-0604 is under active attack, Alien Labs researchers say.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-12884

OX Software GmbH App Suite 7.8.4 and earlier is affected by: Information Exposure.

πŸ“– Read

via "National Vulnerability Database".
❌ News Wrap: Facebook Regulation, Verizon DBIR, Hidden Airbnb Cameras ❌

From a creepy Airbnb incident to Verizon's Data Breach Investigations Report, Threatpost editors break down the top privacy and security stories for the week ended May 10.

πŸ“– Read

via "Threatpost".
πŸ•΄ Demystifying the Dark Web: What You Need to Know πŸ•΄

The Dark Web and Deep Web are not the same, neither is fully criminal, and more await in this guide to the Internet's mysterious corners.

πŸ“– Read

via "Dark Reading: ".
❌ FIN7 Linked to Escalating Active Exploits for Microsoft SharePoint Bug ❌

Using a bug patched in March, the attacks are starting to ramp up worldwide.

πŸ“– Read

via "Threatpost".
⚠ Monday review – the hot 18 stories of the week ⚠

From spying Airbnb creeps to the CSS trick that tracks your mouse movements - and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Break up Facebook, cofounder says: it’s an un-American monopoly ⚠

During the 2018 "annus horribilis", users disgusted at privacy flops swore to dump Facebook. But where else is there to go?

πŸ“– Read

via "Naked Security".
⚠ Study finds Android smartphones riddled with suspect β€˜bloatware’ ⚠

According to a new study, Android bloatware can create hidden security and privacy risks.

πŸ“– Read

via "Naked Security".
⚠ Two Chinese hackers indicted for massive Anthem breach ⚠

They're part of a gang that spearphished millions of records out of the health insurer and other businesses, the DOJ says.

πŸ“– Read

via "Naked Security".
πŸ” Top 5 challenges keeping IT pros up at night πŸ”

IT professionals face a slew of concerns in today's connected ecosystem, according to an Insight Enterprises report.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-12303

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12302

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12301

Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12300

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12299

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

πŸ“– Read

via "National Vulnerability Database".