🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Proving the Value of Security Awareness with Metrics that 'Deserve More' 🕴

Without metrics that matter to the business, awareness programs will continue to be the bastard child of security.

📖 Read

via "Dark Reading: ".
🕴 Google Alerts Admins to Unhashed Password Storage 🕴

The company reports it has seen improper access to, or misuse of, affected enterprise G Suite credentials.

📖 Read

via "Dark Reading: ".
🕴 Baltimore Email, Other Systems Still Offline from May 7 Ransomware Attack 🕴

The city's mayor says there's no 'exact timeline on when all systems will be restored.'

📖 Read

via "Dark Reading: ".
🔏 Lithuanian DPA Hopes First GDPR Fine Is A Wake Up Call 🔏

It took a year but Lithuania's data protection authority issued its first fine, to a fintech company, for breaching three provisions of the GDPR.

📖 Read

via "Subscriber Blog RSS Feed ".
WannaCry-Infested Laptop Starts at $1.13M in Art Auction

The "bestiary" houses six historical threats that combined resulted in at least $95B in damages worldwide.

📖 Read

via "Threatpost".
ATENTION New - CVE-2018-7202

An issue was discovered in ProjectSend before r1053. XSS exists in the "Name" field on the My Account page.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2018-14729

The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2018-12886

stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targeting ARM targets that spill the address of the stack protector guard, which allows an attacker to bypass the protection of -fstack-protector, -fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit against stack overflow by controlling what the stack canary is compared against.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-9809

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Information Exposure.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-6514 (wordpress)

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

📖 Read

via "National Vulnerability Database".
🕴 Data Asset Management: What Do You Really Need? 🕴

At Interop, a cybersecurity and privacy leader explains her approach to data management and governance at a massive, decentralized company.

📖 Read

via "Dark Reading: ".
🕴 New Software Skims Credit Card Info From Online Credit Card Transactions 🕴

The new exploit builds a fake frame around legitimate portions of an online commerce website.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2017-9808

OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Cross Site Scripting (XSS).

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-8777

Open-Xchange GmbH OX Cloud Plugins 1.4.0 and earlier is affected by: Missing Authorization.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-8341

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Content Spoofing.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-8340

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-6912

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-5984

In libavcodec in Libav 9.21, ff_h264_execute_ref_pic_marking() has a heap-based buffer over-read.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-5871

Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-5864

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Cross Site Scripting (XSS).

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2017-5863

Open-Xchange GmbH OX App Suite 7.8.3 and earlier is affected by: Incorrect Access Control.

📖 Read

via "National Vulnerability Database".