πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 7 Recent Wins Against Cybercrime πŸ•΄

The increasing number of successful law enforcement actions and prosecutions suggest that cybercriminals have plenty of reason to be looking over their shoulders.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Master NSA-Grade Security Tools at New Black Hat Trainings Virginia πŸ•΄

Get ready, because this October Black Hat will bring its highly-regarded Trainings to Alexandria, Virginia for two days of intensive, practical cybersecurity education.

πŸ“– Read

via "Dark Reading: ".
❌ News Wrap: Which Companies Are Doing Privacy Right and Which Aren’t? ❌

The Threatpost team breaks down the top privacy-related data incidents of the week - including data leaks from HCL and a golfing app - and highlights some surprisingly good privacy news.

πŸ“– Read

via "Threatpost".
πŸ” Oh Canada: Why half of phishing attacks target the Great White North πŸ”

Though phishing volume remained relatively stable, attacks against Canadian users dominate, according to an RSA report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ How Security Vendors Can Address the Cybersecurity Talent Shortage πŸ•΄

The talent gap is too large for any one sector, and cybersecurity vendors have a big role to play in helping to close it.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Moody's Downgrade of Equifax: A Wake-up Call to Boards πŸ•΄

The event provides another spark to light a fire under CISOs to improve how they measure and communicate security risks to the board, security experts say.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NSS Labs Admits Its Test of CrowdStrike Falcon Was 'Inaccurate' πŸ•΄

CrowdStrike, NSS Labs reach confidential settlement over 2017 endpoint product testing dispute.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Mist Computing Startup Distributes Security AI to the Network Edge πŸ•΄

MistNet, founded by former Juniper employees, moves AI processing to the network edge to build distributed detection and analysis models for security.

πŸ“– Read

via "Dark Reading: ".
❌ Microsoft Beefs Up Wi-Fi Protection ❌

The Windows 10 update that's rolling out addresses insecure Wi-Fi hotspots with new user notifications.

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 5/24 Edition πŸ”

Google's password faux pas, how real-time bidding may violate the GDPR, and tips on mitigating trade theft risk are all covered in this week's Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Joomla and WordPress Found Harboring Malicious Redirect Code ❌

New .htaccess injector threat on Joomla and WordPress websites redirects to malicious websites.

πŸ“– Read

via "Threatpost".
πŸ” What the future looks like as GDPR's one-year anniversary approaches πŸ”

ZDNet's Danny Palmer sits down with TechRepublic's Karen Roby to break down exactly what GDPR is, what it does, and what the future looks like as its one-year anniversary approaches.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2016-8900

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-8898

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10245

Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-site scripting or iframe injection.

πŸ“– Read

via "National Vulnerability Database".
❌ Snapchat Privacy Blunder Piques Concerns About Insider Threats ❌

After a report found that Snap employees were abusing their access to Snapchat data, experts are warning that insider threats will continue to be a top challenge for privacy.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-10759

The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks .php uploads.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10758

PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10757

In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution via addons/cronjob/lib/types/phpcode.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10756

Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configure the uploading of .php files, and then modules/upload/upload_main.php can be used for the upload itself.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10755

AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.

πŸ“– Read

via "National Vulnerability Database".