πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-7559

It was found that the Apache ActiveMQ client before 5.15.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-8183

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7474

Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7473

Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to use a Yubikey on Linux with an encrypted drive πŸ”

Looking to use a Yubikey for added security on your encrypted Linux drives? With a few quick commands, you'll enjoy that added layer of security.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Demystifying New FIDO Standards & Innovations πŸ•΄

Staying on top of the latest cybersecurity risks and preferred attack methods can feel impossible, but standards like FIDO2 are designed to help relieve the burden.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Researcher Find Open 'Road Map' to Honda Computers πŸ•΄

An unprotected database, now secured, contained information on every computer owned by the automobile giant.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10824

cPanel before 55.9999.141 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-90).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10823

cPanel before 55.9999.141 allows arbitrary code execution in the context of the root account because of MakeText interpolation (SEC-89).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10822

cPanel before 55.9999.141 allows self XSS in X3 Reseller Branding Images (SEC-88).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 1M Payment Cards Exposed in South Korea Breach πŸ•΄

South Korea is the largest victim of card present data theft at a time when criminals are ramping up cyberattacks in the Asia-Pacific region.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10815

cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10814

cPanel before 57.9999.54 allows demo-mode escape via show_template.stor (SEC-119).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10813

cPanel before 57.9999.54 allows self XSS during ftp account creation under addon domains (SEC-118).

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ PCI Security Council, Retail ISAC Warn Retailers on Magecart Attacks πŸ•΄

Online card-skimming activities grew sharply this summer fueled by the availability of attack kits and other factors, Malwarebytes says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ DARPA to Bring its Smart Ballot Boxes to DEF CON for Hacking πŸ•΄

The agency this week will share the source code and hardware specifications for the secure voting system prototypes.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Cisco Pays $8.6M in First False Claims Suit for Vulnerabilities in Security Product πŸ•΄

A security consultant reported vulnerabilities in Cisco's Video Surveillance Manager in 2009 - but the company ignored the issues and fired the consultant.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 47% of Android Anti-Malware Apps Are Flawed πŸ•΄

Protection failures come at a time when malicious Android software is becoming more of a problem.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why Every Organization Needs an Incident Response Plan πŸ•΄

OK, perhaps that's self-evident, so how come it far too often still takes an incident to trigger planning?

πŸ“– Read

via "Dark Reading: ".
⚠ Facebook is working on mind-reading ⚠

The completely non-evil-genius goal: a wearable, noninvasive device that could translate thoughts into text, for the speech impaired or VR.

πŸ“– Read

via "Naked Security".
⚠ Anime filter glitches, exposing face of one extremely smart vlogger ⚠

Pretending to be a hot young thing brought in beaucoup bucks. Last laugh department: "world's best granny" now has more followers than ever.

πŸ“– Read

via "Naked Security".