πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2013-7471

An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injection via shell metacharacters in the NewInternalClient, NewExternalPort, or NewInternalPort element of a SOAP POST request.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5330

On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not sanitized, as demonstrated by shell metacharacters. The fixed version is v4.0.1 for 802.11 ISP products, v5.3.5 for AirMax ISP products, and v5.4.5 for AirSync firmware. For example, Nanostation5 (Air OS) is affected.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5157

On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c4_ping_ipaddr variable.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5156

An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query string.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cross-Site Scripting Errors Continue to Be Most Common Web App Flaw πŸ•΄

In vulnerability disclosure programs, organizations are paying more in total for XSS issues than any other vulnerability type, HackerOne says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Suppliers Spotlighted After Breach of Border Agency Subcontractor πŸ•΄

Attackers increasingly use third-party service providers to bypass organizations' security. The theft of images from US Customs and Border Protection underscores the weakness suppliers can create.

πŸ“– Read

via "Dark Reading: ".
⚠ Hackers stole photos of travelers and license plates from subcontractor ⚠

Critics say if the US can't protect such data - which was improperly stored by a subcontractor - it shouldn't collect it.

πŸ“– Read

via "Naked Security".
⚠ Radiohead releases β€˜OK Computer’ sessions that hacker tried to ransom ⚠

The band shrugged off the threat and released the files on Bandcamp. They're long and not very interesting, they said.

πŸ“– Read

via "Naked Security".
⚠ FBI warns users to be wary of phishing sites abusing HTTPS ⚠

Why you shouldn't trust a website simply because it's secured using HTTPS and backed by the green padlock symbol.

πŸ“– Read

via "Naked Security".
❌ Full Insight into the Internal Environment with Cynet Free Visibility ❌

The Cynet 360 platform Free Visibility Offering is focused on IT and security professionals who know a lack of visibility is a main challenge in their daily responsibilities as end-users and service providers. 

πŸ“– Read

via "Threatpost".
❌ Full Insight into the Internal Environment with Cynet Free Visibility ❌

The Cynet 360 platform Free Visibility Offering is focused on IT and security professionals who know a lack of visibility is a main challenge in their daily responsibilities as end-users and service providers. 

πŸ“– Read

via "Threatpost".
❌ New FormBook Dropper Harbors Obfuscation, Persistence ❌

Never-before-seen dropper found in FormBook samples that has increased persistence and obfuscation capabilities.

πŸ“– Read

via "Threatpost".
πŸ” 84% of US employees have never heard of GDPR πŸ”

A survey of corporate employees by insider threat management company ObserveIT reveals a greater understanding of privacy laws in the UK than in the US.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Evernote Chrome extension vulnerability allowed attackers to steal 4.7M users' data πŸ”

A cross-site scripting vulnerability was discovered popular note-taking application Evernote, though the company patched it in under a week.

πŸ“– Read

via "Security on TechRepublic".
❌ Intel NUC Firmware Open to Privilege Escalation, DoS and Information Disclosure ❌

Intel has patched seven high-severity vulnerabilities in its mini PC NUC kit firmware.

πŸ“– Read

via "Threatpost".
πŸ•΄ Predicting Vulnerability Weaponization πŸ•΄

Advances in data science are making it possible to shift vulnerability management from a reactive to a proactive discipline.

πŸ“– Read

via "Dark Reading: ".
⚠ Critical Adobe Flash player bug and more in June’s Patch Tuesday ⚠

June patch Tuesday features fixes from Adobe and Microsoft for critical flaws including a remote code vulnerability in Adobe Flash Player.

πŸ“– Read

via "Naked Security".
πŸ” How to secure your LinkedIn profile πŸ”

LinkedIn offers many privacy and security options that professionals may not be aware of. Here's what you need to know to stay safe on the networking platform.

πŸ“– Read

via "Security on TechRepublic".
πŸ” LaLiga facing €250k fine for GDPR violations in app used to spy on users πŸ”

The official app of the Spanish soccer league used the microphone and GPS in an attempt to curb restaurants from broadcasting the game.

πŸ“– Read

via "Security on TechRepublic".
❌ RAMBleed Side-Channel Attack Exposes Privileged Memory ❌

An attacker can use Rowhammer attacker to induce bit flips, thereby leaking the victim's secret data via a side channel.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2017-15123

A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.

πŸ“– Read

via "National Vulnerability Database".