πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26.1K subscribers
89.3K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2017-18608

The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18607

The avada theme before 5.1.5 for WordPress has CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18606

The avada theme before 5.1.5 for WordPress has stored XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18605

The gravitate-qa-tracker plugin through 1.2.1 for WordPress has PHP Object Injection.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18604

The sitebuilder-dynamic-components plugin through 1.0 for WordPress has PHP object injection via an AJAX request.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18603

The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18602

The examapp plugin 1.0 for WordPress has SQL injection via the wp-admin/admin.php?page=examapp_UserResult id parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18601

The examapp plugin 1.0 for WordPress has XSS via exam input text fields.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2017-18600

The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Gartner proposes framework to manage regulations for our digital society πŸ”

The myriad rules and regulations that govern data protection and privacy need some type of framework to tie them together in our cyber society.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ US Power Grid Cyberattack Due to Unpatched Firewall: NERC πŸ•΄

A firewall vulnerability enabled attackers to repeatedly reboot the victim entity's firewalls, causing unexpected outages.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Data Is the New Copper πŸ•΄

Data breaches fuel a complex cybercriminal ecosystem, similar to copper thefts after the financial crisis.

πŸ“– Read

via "Dark Reading: ".
❌ Adobe Fixes Critical Flash Player Code Execution Flaws ❌

Overall Adobe's September security update addressed vulnerabilities in Flash Player and Application Manager.

πŸ“– Read

via "Threatpost".
πŸ” Solid State Drive Trade Secrets Behind Latest Huawei Case πŸ”

Prosecutors in the U.S. are pursuing criminal charges against a Chinese professor after he purportedly took trade secrets to benefit Huawei. The case is yet another instance of the Department of Justice taking its investigation around Huawei, not to mention the theft of trade secrets, seriously.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ ThreatList: Amidst Data Breaches, Account Creation Fraud Soars in 2019 ❌

Cybercrooks are using bots to create synthetic digital identities, to carry out various types of fraud.

πŸ“– Read

via "Threatpost".
❌ Microsoft Addresses Two Zero-Days Under Active Attack ❌

September Patch Tuesday leads off with two elevation-of-privilege bugs that have been exploited in the wild.

πŸ“– Read

via "Threatpost".
❌ Insider Threats Are Rising – But They Shouldn’t Be ❌

Simply implementing best practices is not enough to address the risk coming from your own employees.

πŸ“– Read

via "Threatpost".
πŸ•΄ New Privacy Features in iOS 13 Let Users Limit Location Tracking πŸ•΄

Apple will introduce other features that allow more secure use of iPhones in workplace settings as well.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Security Pros' Painless Guide to Machine Intelligence, AI, ML & DL πŸ•΄

Artificial intelligence, machine learning or deep learning? Knowing what the major terms really mean will help you sort through the morass of words on the subject and the security uses of each.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Two Zero-Days Fixed in Microsoft Patch Rollout πŸ•΄

September's Patch Tuesday addressed 80 vulnerabilities, two of which have already been exploited in the wild.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Third-Party Features Leave Websites More Vulnerable to Attack πŸ•΄

A new report points out the dangers to customer data of website reliance on multiple third parties.

πŸ“– Read

via "Dark Reading: ".