πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Elderly China Chopper Tool Still Going Strong in Multiple Campaigns ❌

Multiple actors in multiple campaigns are using the web shell for remote access, even though it's almost a decade old and hasn't been updated.

πŸ“– Read

via "Threatpost".
πŸ” How to use Harbor to scan Docker images for vulnerabilities πŸ”

Make sure you're not deploying containers based on vulnerable images by scanning those images with Harbor.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to use Harbor to scan Docker images for vulnerabilities πŸ”

Make sure you're not deploying containers based on vulnerable images by scanning those images with Harbor.

πŸ“– Read

via "Security on TechRepublic".
⚠ Microsoft may still be violating privacy rules, says Dutch regulator ⚠

EU data watchdogs are yet again sniffing at Windows 10.

πŸ“– Read

via "Naked Security".
⚠ Video captures glitching Mississippi voting machines flipping votes ⚠

A video that shows an electronic machine switching voters' selections has gone viral, underscoring the need for paper audit trails.

πŸ“– Read

via "Naked Security".
❌ Innovation on the Dark Web: How Bad Actors Are Keeping Pace ❌

How criminals have adapted to develop the next generation of dark markets and operations.

πŸ“– Read

via "Threatpost".
πŸ” Phishing attacks jump by 21% in latest quarter, says Kaspersky πŸ”

The number of worldwide phishing attacks detected by Kaspersky hit 129.9 million during the second quarter of 2019, according to a new report from the security vendor.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Cybersecurity analysts overworked, undertrained and buckling under volume of alerts πŸ”

The majority of security operations center professionals said the job is now simply about reducing alert investigation time or the volume of alerts.

πŸ“– Read

via "Security on TechRepublic".
❌ Critical Cisco VM Bug Allows Remote Takeover of Routers ❌

CVE-2019-12643 has been given the highest possible severity rating.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9334 (email-newsletter)

The email-newsletter plugin through 20.15 for WordPress has SQL injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10394 (rich_counter)

The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10391 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10390 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10389 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10388 (wp_support_plus_responsive_ticket_system)

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10386 (wp_live_chat_support)

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-10382 (featured_comments)

The feature-comments plugin before 1.2.5 for WordPress has CSRF for featuring or burying a comment.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-7483 (slidedeck_2)

The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.

πŸ“– Read

via "National Vulnerability Database".
⚠ Web clickjacking fraud makes a comeback thanks to JavaScript tricks ⚠

More than a decade after hitting the headlines, clickjacking fraud remains an under-reported hazard on hundreds of popular websites.

πŸ“– Read

via "Naked Security".
πŸ•΄ Privacy 2019: We're Not Ready πŸ•΄

To facilitate the innovative use of data and unlock the benefits of new technologies, we need privacy not just in the books but also on the ground.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Fuzzing 101: Why Bug Hunters Still Love It After All These Years πŸ•΄

Fuzzing is one of the basic tools in a researcher's arsenal. Here are the things you should know about this security research foundational tool.

πŸ“– Read

via "Dark Reading: ".