πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9297

The events-manager plugin before 5.6 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9296

The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9295

The contact-form-plugin plugin before 3.96 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9294

The all-in-one-wp-security-and-firewall plugin before 3.9.5 for WordPress has XSS in add_query_arg and remove_query_arg function instances.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9293

The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7475

The contact-form-plugin plugin before 3.52 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-6713

The job-manager plugin before 0.7.19 for WordPress has multiple XSS issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Internet Routing Security Initiative Launches Online 'Observatory' πŸ•΄

Mutually Agreed Norms for Routing Security (MANRS) lets network operators and the public view online router incidents worldwide.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to change a root password in a Docker image πŸ”

If you deploy Docker containers based on an official imagine, you might want to set a root password for heightened security.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Think Tank: Standard Contractual Clauses for International Transfers Should Mirror GDPR πŸ”

The Centre for Information Policy Leadership issued a lengthy white paper last week highlighting challenges and recommendations around standard contractual clauses (SCCs) for international data transfers.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ 22 Critical Flaws Patched in Adobe Photoshop ❌

Patched critical flaws in Adobe's Photoshop CC photo editing application enable arbitrary code execution.

πŸ“– Read

via "Threatpost".
πŸ•΄ Barracuda Buys Bot-Battling Tech from InfiSecure πŸ•΄

The intellectual property acquired will add to Barracuda's bot-detection capabilities.

πŸ“– Read

via "Dark Reading: ".
❌ Shades of BlueKeep: Wormable Remote Desktop Bugs Top August Patch Tuesday List ❌

The flaws allow remote code-execution without user interaction or authentication, and are highly exploitable.

πŸ“– Read

via "Threatpost".
πŸ•΄ Microsoft Patches Wormable RCE Vulns in Remote Desktop Services πŸ•΄

Similar to the now-patched 'BlueKeep' vulnerability, two flaws fixed today could let malware spread across vulnerable computers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Orgs Doing More App Security Testing but Fixing Fewer Vulns πŸ•΄

On average, US organizations took nearly five months to fix critical vulnerabilities according to WhiteHat Security's annual vulnerability report.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Does Personality Make You Vulnerable to Cybercrime? πŸ•΄

A new study explores the connections between personality traits and susceptibility to different cyberattacks.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Apple's New Bounty Program Has Huge Incentives, Big Risks πŸ•΄

Industry observers applaud the program's ability to find exploits but fear unintended consequences.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2014-10375

handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.

πŸ“– Read

via "National Vulnerability Database".
⚠ Coinbase explains background to June zero-day Firefox attack ⚠

A recent, highly targeted attack on cryptocurrency exchange Coinbase offers a glimpse into how sophisticated phishing attacks can be.

πŸ“– Read

via "Naked Security".
πŸ•΄ You Gotta Reach 'Em to Teach 'Em πŸ•΄

As threats continue to evolve and cybercriminals become more sophisticated, organizations that lack a mature security awareness and training program place themselves at serious risk.

πŸ“– Read

via "Dark Reading: ".
⚠ Fortnite World Cup champion and family swatted while live streaming ⚠

"They come in with guns, bro. They literally pulled up, holy sh*t."

πŸ“– Read

via "Naked Security".