πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Magecart Shops for Victims as E-Commerce Market Grows πŸ•΄

In 2.5 hours of research, one security expert uncovered more than 80 actively compromised ecommerce websites.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Facebook Patches Second Account-Takeover Flaw in Instagram πŸ•΄

The password-recovery mechanism once again puts users of the photo- and video-sharing platform at risk.

πŸ“– Read

via "Dark Reading: ".
❌ Elderly China Chopper Tool Still Going Strong in Multiple Campaigns ❌

Multiple actors in multiple campaigns are using the web shell for remote access, even though it's almost a decade old and hasn't been updated.

πŸ“– Read

via "Threatpost".
πŸ” How to use Harbor to scan Docker images for vulnerabilities πŸ”

Make sure you're not deploying containers based on vulnerable images by scanning those images with Harbor.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to use Harbor to scan Docker images for vulnerabilities πŸ”

Make sure you're not deploying containers based on vulnerable images by scanning those images with Harbor.

πŸ“– Read

via "Security on TechRepublic".
⚠ Microsoft may still be violating privacy rules, says Dutch regulator ⚠

EU data watchdogs are yet again sniffing at Windows 10.

πŸ“– Read

via "Naked Security".
⚠ Video captures glitching Mississippi voting machines flipping votes ⚠

A video that shows an electronic machine switching voters' selections has gone viral, underscoring the need for paper audit trails.

πŸ“– Read

via "Naked Security".
❌ Innovation on the Dark Web: How Bad Actors Are Keeping Pace ❌

How criminals have adapted to develop the next generation of dark markets and operations.

πŸ“– Read

via "Threatpost".
πŸ” Phishing attacks jump by 21% in latest quarter, says Kaspersky πŸ”

The number of worldwide phishing attacks detected by Kaspersky hit 129.9 million during the second quarter of 2019, according to a new report from the security vendor.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybersecurity analysts overworked, undertrained and buckling under volume of alerts πŸ”

The majority of security operations center professionals said the job is now simply about reducing alert investigation time or the volume of alerts.

πŸ“– Read

via "Security on TechRepublic".
❌ Critical Cisco VM Bug Allows Remote Takeover of Routers ❌

CVE-2019-12643 has been given the highest possible severity rating.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9334 (email-newsletter)

The email-newsletter plugin through 20.15 for WordPress has SQL injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10394 (rich_counter)

The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10391 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10390 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10389 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10388 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10386 (wp_live_chat_support)

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10382 (featured_comments)

The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7483 (slidedeck_2)

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

πŸ“– Read

via "National Vulnerability Database".
⚠ Web clickjacking fraud makes a comeback thanks to JavaScript tricks ⚠

More than a decade after hitting the headlines, clickjacking fraud remains an under-reported hazard on hundreds of popular websites.

πŸ“– Read

via "Naked Security".