🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Taking a Fresh Look at Security Ops: 10 Tips 🕴

Maybe you love your executive team, your security processes, tools, or strategy. Maybe you hate them. Whatever the situation, it's likely at some point that things will have changed.

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2016-10955

The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10954

The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10953

The Headway theme before 3.8.9 for WordPress has XSS via the license key field.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10952

The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10951

The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10950

The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10949

The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10948

The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10947

The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10946

The wp-d3 plugin before 2.4.1 for WordPress has CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10945

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10944

The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10943

The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10942

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10941

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10940

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10939

The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10938

The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.

📖 Read

via "National Vulnerability Database".
🔐 Cybercrimninals set sights on bot attacks and mobile apps 🔐

The past six months have seen a 13% increase in human-initiated cyberattacks. Here's what cybercriminals are targeting.

📖 Read

via "Security on TechRepublic".
🔏 Friday Five: 9/13 Edition 🔏

Hackers hit a U.S. power utility, a new audit on whether schools are monitoring employee access to student data, and more - catch up on the week's news with the Friday Five!

📖 Read

via "Subscriber Blog RSS Feed ".