πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2016-10937

IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

πŸ“– Read

via "National Vulnerability Database".
⚠ Patch early, patch often – and patch everything! ⚠

Here's our latest Naked Security Live video - all about WordPress, plugins and patching.

πŸ“– Read

via "Naked Security".
⚠ Monday review – the hot 21 stories of the week ⚠

From backdooring WordPress sites to Raspberry Pi in space, and everything in between. It's weekly roundup time.

πŸ“– Read

via "Naked Security".
⚠ US city balks at paying $5.3 million ransomware demand ⚠

The attack quickly encrypted 158 workstations - and would have been worse had it struck later in the working day.

πŸ“– Read

via "Naked Security".
⚠ Facebook launches $10m deepfake detection project ⚠

If you're worried about the evil potential of deepfake video, you're not alone; so is Facebook.

πŸ“– Read

via "Naked Security".
⚠ Brave accuses Google of sidestepping GDPR ⚠

A senior executive at private browser company Brave has accused Google of using a workaround that lets it identify users to ad networks.

πŸ“– Read

via "Naked Security".
⚠ WordPress 5.2.3 fixes new clutch of security vulnerabilities ⚠

WordPress version 5.2.3 has just appeared on the download pipe featuring half a dozen security fixes and software enhancements.

πŸ“– Read

via "Naked Security".
❌ Apple Claims Google is Spreading FUD Over Patched iPhone Bugs ❌

Apple said Google’s recent analysis of vulnerabilities found January in iOS painted a misleading picture of the scope of the attacks and the risk involved

πŸ“– Read

via "Threatpost".
πŸ•΄ Phishers' Latest Tricks for Reeling in New Victims πŸ•΄

Phishing works because people are, by nature, trusting -- but these evolving phishing techniques make it even tougher for security managers to stay on top.

πŸ“– Read

via "Dark Reading: ".
πŸ” Google hopes to protect users with open source differential privacy library πŸ”

Google's differential privacy library will give organizations a way to study their data while protecting people's information.

πŸ“– Read

via "Security on TechRepublic".
❌ Critical Exim Flaw Opens Millions of Servers to Takeover ❌

A critical vulnerability found in Exim servers could enable a remote, unauthenticated attacker to execute arbitrary code with root privileges.

πŸ“– Read

via "Threatpost".
πŸ•΄ From Spyware to Ninja Cable πŸ•΄

Attackers don't need sophisticated James Bondian hardware to break into your company. Sometimes a $99 device will do.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-10666

An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the include() function on user supplied input without sanitizing the values by calling basename() or a similar function. An attacker can leverage this to execute PHP code from the included file. Exploitation of these scripts is made difficult by additional text being appended (typically .inc.php), which means an attacker would need to be able to control both a filename and its content on the server. However, exploitation can be achieved as demonstrated by the csv.php?report=../ substring.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2019-10665

An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php script. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, file content, denial of service, or writing arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21014

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21013

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21012

The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21011

The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Just A Few Questions Before That Bank Withdrawal ... πŸ•΄

And be ready to turn over your first born.

πŸ“– Read

via "Dark Reading: ".
πŸ” Millions of Exim Servers Vulnerable to Remote Code Execution Vulnerability πŸ”

A critical vulnerability in Exim, by far the world's most popular email server, was disclosed on Friday.

πŸ“– Read

via "Subscriber Blog RSS Feed ".