πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Tech news roundup: GDPR turns 1, and who makes the best apps? πŸ”

Karen Roby reports on this week's biggest tech news, including Huawei's Android license and the one year anniversary of GDPR. How have businesses been affected by the legislation and what does Microsoft have to say about a potential version of the law in the US?

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2018-1991

IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10750

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

πŸ“– Read

via "National Vulnerability Database".
❌ Critical Flaws in Khan Academy Opened Door to Account Takeovers ❌

The two critical cross-site request forgery flaws in the online learning non-profit Khan Academy have been resolved.

πŸ“– Read

via "Threatpost".
πŸ•΄ DDoS Attacks Up in Q1 After Months of Steady Decline πŸ•΄

Sudden surge suggests that new actors have stepped up to the plate to replace the old operators.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Proving the Value of Security Awareness with Metrics that 'Deserve More' πŸ•΄

Without metrics that matter to the business, awareness programs will continue to be the bastard child of security.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Google Alerts Admins to Unhashed Password Storage πŸ•΄

The company reports it has seen improper access to, or misuse of, affected enterprise G Suite credentials.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Baltimore Email, Other Systems Still Offline from May 7 Ransomware Attack πŸ•΄

The city's mayor says there's no 'exact timeline on when all systems will be restored.'

πŸ“– Read

via "Dark Reading: ".
πŸ” Lithuanian DPA Hopes First GDPR Fine Is A Wake Up Call πŸ”

It took a year but Lithuania's data protection authority issued its first fine, to a fintech company, for breaching three provisions of the GDPR.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ WannaCry-Infested Laptop Starts at $1.13M in Art Auction ❌

The "bestiary" houses six historical threats that combined resulted in at least $95B in damages worldwide.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2018-7202

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-14729

The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-12886

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-9809

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-6514 (wordpress)

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Data Asset Management: What Do You Really Need? πŸ•΄

At Interop, a cybersecurity and privacy leader explains her approach to data management and governance at a massive, decentralized company.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Software Skims Credit Card Info From Online Credit Card Transactions πŸ•΄

The new exploit builds a fake frame around legitimate portions of an online commerce website.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2017-9808

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-8777

Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-8341

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-8340

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

πŸ“– Read

via "National Vulnerability Database".