🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2015-9299

The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9298

The events-manager plugin before 5.6 for WordPress has code injection.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9297

The events-manager plugin before 5.6 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9296

The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9295

The contact-form-plugin plugin before 3.96 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9294

The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9293

The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2013-7475

The contact-form-plugin plugin before 3.52 for WordPress has XSS.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2012-6713

The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.

📖 Read

via "National Vulnerability Database".
🕴 Internet Routing Security Initiative Launches Online 'Observatory' 🕴

Mutually Agreed Norms for Routing Security (MANRS) lets network operators and the public view online router incidents worldwide.

📖 Read

via "Dark Reading: ".
🔐 How to change a root password in a Docker image 🔐

If you deploy Docker containers based on an official imagine, you might want to set a root password for heightened security.

📖 Read

via "Security on TechRepublic".
🔏 Think Tank: Standard Contractual Clauses for International Transfers Should Mirror GDPR 🔏

The Centre for Information Policy Leadership issued a lengthy white paper last week highlighting challenges and recommendations around standard contractual clauses (SCCs) for international data transfers.

📖 Read

via "Subscriber Blog RSS Feed ".
22 Critical Flaws Patched in Adobe Photoshop

Patched critical flaws in Adobe's Photoshop CC photo editing application enable arbitrary code execution.

📖 Read

via "Threatpost".
🕴 Barracuda Buys Bot-Battling Tech from InfiSecure 🕴

The intellectual property acquired will add to Barracuda's bot-detection capabilities.

📖 Read

via "Dark Reading: ".
Shades of BlueKeep: Wormable Remote Desktop Bugs Top August Patch Tuesday List

The flaws allow remote code-execution without user interaction or authentication, and are highly exploitable.

📖 Read

via "Threatpost".
🕴 Microsoft Patches Wormable RCE Vulns in Remote Desktop Services 🕴

Similar to the now-patched 'BlueKeep' vulnerability, two flaws fixed today could let malware spread across vulnerable computers.

📖 Read

via "Dark Reading: ".
🕴 Orgs Doing More App Security Testing but Fixing Fewer Vulns 🕴

On average, US organizations took nearly five months to fix critical vulnerabilities according to WhiteHat Security's annual vulnerability report.

📖 Read

via "Dark Reading: ".
🕴 Does Personality Make You Vulnerable to Cybercrime? 🕴

A new study explores the connections between personality traits and susceptibility to different cyberattacks.

📖 Read

via "Dark Reading: ".
🕴 Apple's New Bounty Program Has Huge Incentives, Big Risks 🕴

Industry observers applaud the program's ability to find exploits but fear unintended consequences.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2014-10375

handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.

📖 Read

via "National Vulnerability Database".
Coinbase explains background to June zero-day Firefox attack

A recent, highly targeted attack on cryptocurrency exchange Coinbase offers a glimpse into how sophisticated phishing attacks can be.

📖 Read

via "Naked Security".