πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” 100+ IT policies at your fingertips, ready for download πŸ”

From BYOD and social media to ergonomics and encryption, TechRepublic has dozens of ready-made, downloadable IT policy templates.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 4 Network Security Mistakes Bound to Bite You πŸ•΄

It's Shark Week again! Are you ready to outmaneuver sharks of the cyber variety? These tips can help.

πŸ“– Read

via "Dark Reading: ".
❌ Fearing WannaCry-Level Danger, Enterprises Wrestle with BlueKeep ❌

Fears of a WannaCry-level global attack grow as working exploit info starts to go public.

πŸ“– Read

via "Threatpost".
❌ β€˜URGENT/11’ Critical Infrastructure Bugs Threaten EternalBlue-Style Attacks ❌

Researchers have uncovered easy-to-exploit bugs that can impact physical safety, utilities, healthcare, critical infrastructure and more, setting the stage for widespread worm attacks.

πŸ“– Read

via "Threatpost".
πŸ” Vulnerability in VxWorks RTOS allows attackers to control internal networks πŸ”

Internet-connected devices powered by VxWorks 6.5 and newer are affected by a vulnerability that allows remote attackers full control over targeted devices.

πŸ“– Read

via "Security on TechRepublic".
❌ Cloud Security Concerns Loom for 93% of Businesses Adopting Apps and BYOD ❌

Threatpost talks to Jacob Serpa with Bitglass about how more enterprises are struggling with a cloud security conundrum when it comes to public cloud vs on prem.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-10766

edx-platform before 2016-06-06 allows CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10765

edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9288

The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-6960

edx-platform before 2015-09-17 allows XSS via a team name.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-6253

edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-5601

edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

πŸ“– Read

via "National Vulnerability Database".
πŸ” What's the Cost of a Data Breach in 2019? πŸ”

The answer ultimately depends on the country and industry but in general, can span anywhere from $1.25 million to $8.19 million.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Sephora Offers Monitoring Services in Wake of Data Breach πŸ•΄

The data breach compromised data belonging to customers in parts of Southeast Asia, Australia, and New Zealand.

πŸ“– Read

via "Dark Reading: ".
❌ ThreatList: DMARC Adoption Nonexistent at 80% of Orgs ❌

Standard email authentication to prevent spoofing and phishing remains elusive for most.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2018-17213

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. A user without valid credentials can bypass the authentication process, obtaining a valid session cookie with guest/pseudo-guest level privileges. This cookie can then be further used to perform other attacks.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-17211

An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. An unauthenticated attacker can view details about the printers associated with CPS via a crafted HTTP GET request.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11774

Apache VCL versions 2.1 through 2.5 do not properly validate form input when adding and removing VMs to and from hosts. The form data is then used in SQL statements. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11773

Apache VCL versions 2.1 through 2.5 do not properly validate form input when processing a submitted block allocation. The form data is then used as an argument to the php built in function strtotime. This allows for an attack against the underlying implementation of that function. The implementation of strtotime at the time the issue was discovered appeared to be resistant to a malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-11772

Apache VCL versions 2.1 through 2.5 do not properly validate cookie input when determining what node (if any) was previously selected in the privilege tree. The cookie data is then used in an SQL statement. This allows for an SQL injection attack. Access to this portion of a VCL system requires admin level rights. Other layers of security seem to protect against malicious attack. However, all VCL systems running versions earlier than 2.5.1 should be upgraded or patched. This vulnerability was found and reported to the Apache VCL project by ADLab of Venustech.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Deutsche Bank Email Vulnerability Left Ex-Employees with Access πŸ•΄

Failures in computer and control systems are being blamed.

πŸ“– Read

via "Dark Reading: ".