πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
⚠ Monday review – the hot 18 stories of the week ⚠

From spying Airbnb creeps to the CSS trick that tracks your mouse movements - and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ Break up Facebook, cofounder says: it’s an un-American monopoly ⚠

During the 2018 "annus horribilis", users disgusted at privacy flops swore to dump Facebook. But where else is there to go?

πŸ“– Read

via "Naked Security".
⚠ Study finds Android smartphones riddled with suspect β€˜bloatware’ ⚠

According to a new study, Android bloatware can create hidden security and privacy risks.

πŸ“– Read

via "Naked Security".
⚠ Two Chinese hackers indicted for massive Anthem breach ⚠

They're part of a gang that spearphished millions of records out of the health insurer and other businesses, the DOJ says.

πŸ“– Read

via "Naked Security".
πŸ” Top 5 challenges keeping IT pros up at night πŸ”

IT professionals face a slew of concerns in today's connected ecosystem, according to an Insight Enterprises report.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-12303

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12302

Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12301

Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12300

Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12299

Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12298

Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12297

Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12296

Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12295

SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Open Testing Standards Can Improve Security πŸ•΄

When creating security metrics, it's critical that test methodologies cover multiple scenarios to ensure that devices perform as expected in all environments.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to use SFTP with a chroot jail πŸ”

Lock down all SFTP users on your data center Linux servers with a chroot jail.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-6652

Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pageflipbook_language parameter.

πŸ“– Read

via "National Vulnerability Database".
❌ ThreatList: Top 5 Most Dangerous Attachment Types ❌

From ZIP attachments spreading Gandcrab, to DOC files distributing Trickbot, researchers tracked five widescale spam campaigns in 2019 that have made use of malicious attachments.

πŸ“– Read

via "Threatpost".
❌ ScarCruft APT Adds Bluetooth Harvester to its Malware Bag of Tricks ❌

In its latest observed campaign, there were also overlaps in victimology with the DarkHotel APT.

πŸ“– Read

via "Threatpost".
πŸ•΄ 78% of Consumers Say Online Companies Must Protect Their Info πŸ•΄

Yet 68% of US consumers agree they also must do more to protect their own information.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Poorly Configured Server Exposes Most Panama Citizens' Data πŸ•΄

Compromised information includes full names, birth dates, national ID numbers, medical insurance numbers, and other personal data.

πŸ“– Read

via "Dark Reading: ".