πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2018-21014

The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21013

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-ajax.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21012

The cf7-invisible-recaptcha plugin before 1.3.2 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2018-21011

The charitable plugin before 1.5.14 for WordPress has unauthorized access to user and donation details.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Just A Few Questions Before That Bank Withdrawal ... πŸ•΄

And be ready to turn over your first born.

πŸ“– Read

via "Dark Reading: ".
πŸ” Millions of Exim Servers Vulnerable to Remote Code Execution Vulnerability πŸ”

A critical vulnerability in Exim, by far the world's most popular email server, was disclosed on Friday.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Wikipedia, World of Warcraft Downed By Weekend DDoS Attacks ❌

Wikipedia and World of Warcraft Classic users reported global outages over the weekend in targeted - and connected - DDoS attacks.

πŸ“– Read

via "Threatpost".
πŸ•΄ Texas Refuses to Pay $2.5M in Massive Ransomware Attack πŸ•΄

The ransomware campaign affected 22 local governments, none of which have paid the attackers' $2.5 million ransom demand.

πŸ“– Read

via "Dark Reading: ".
❌ Telnet Backdoor Opens More Than 1M IoT Radios to Hijack ❌

Attackers can drop malware, add the device to a botnet or send their own audio streams to compromised devices.

πŸ“– Read

via "Threatpost".
πŸ•΄ Public Exposure Does Little to Slow China-Based Thrip APT πŸ•΄

Over the past year, the cyber-espionage group has attacked at least 12 other companies in the military, telecom, and satellite sectors, Symantec says.

πŸ“– Read

via "Dark Reading: ".
❌ Stealth Falcon Targets Middle East with Windows BITS Feature ❌

Cyberespionage attackers have ditched their PowerShell backdoor in favor of the Windows BITS β€˜notification’ feature.

πŸ“– Read

via "Threatpost".
❌ PsiXBot Adds PornModule, Google DNS Service to Its Arsenal ❌

Porn-recording feature will likely be used for extortion.

πŸ“– Read

via "Threatpost".
πŸ” More than 99% of attacks in the past year relied on human error to gain access πŸ”

Experiencing a data breach purely from being internet-connected is quite rare. Hackers rely on users to open or install a malicious payload, according to Proofpoint.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How to set up an SFTP server on Linux πŸ”

These steps walk you through the process of setting up an SFTP server on Linux for the secure transfer of files for specialized file transfer-only users.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Top 5 password alternatives πŸ”

Passwords remain the most common way to authenticate your online identity, but companies like Microsoft and Google are using alternate login methods. Tom Merritt offers five alternatives to passwords.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ More Than 99% of Cyberattacks Need Victims' Help πŸ•΄

Research highlights how most criminals exploit human curiosity and trust to click, download, install, open, and send money or information.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2019-10253

A Cross-Site Request Forgery (CSRF) vulnerability exists in TeamMate+ 21.0.0.0 that allows a remote attacker to modify application data (upload malicious/forged files on a TeamMate server, or replace existing uploaded files with malicious/forged files). The specific flaw exists within the handling of Upload/DomainObjectDocumentUpload.ashx requests because of failure to validate a CSRF token before handling a POST request.

πŸ“– Read

via "National Vulnerability Database".
⚠ Critical TLS flaw opens Exim servers to remote compromise ⚠

A β€˜critical’ security vulnerability has been discovered in the Exim mail server that requires admins' urgent attention.

πŸ“– Read

via "Naked Security".
⚠ Chrome bumps ineffective EV certificates off the omnibar ⚠

Ever notice a missing company name next to the URL address bar? Ever change behavior because of it? Likely not, so bye-bye, useless badge.

πŸ“– Read

via "Naked Security".