🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2016-10945

The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10944

The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10943

The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10942

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id parameter exploitable via CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10941

The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10940

The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10939

The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2016-10938

The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.

📖 Read

via "National Vulnerability Database".
🔐 Cybercrimninals set sights on bot attacks and mobile apps 🔐

The past six months have seen a 13% increase in human-initiated cyberattacks. Here's what cybercriminals are targeting.

📖 Read

via "Security on TechRepublic".
🔏 Friday Five: 9/13 Edition 🔏

Hackers hit a U.S. power utility, a new audit on whether schools are monitoring employee access to student data, and more - catch up on the week's news with the Friday Five!

📖 Read

via "Subscriber Blog RSS Feed ".
Astaroth Spy Trojan Uses Facebook, YouTube Profiles to Cover Tracks

At every turn, the info-stealer uses legitimate services to get around normal email, endpoint and network defenses.

📖 Read

via "Threatpost".
🕴 No Quick Fix for Security-Worker Shortfall 🕴

Security professionals see acquiring skills as the way forward, but only half of companies are training their workers, with more continuing to search for highly skilled employees.

📖 Read

via "Dark Reading: ".
🕴 6 Questions to Ask Once You've Learned of a Breach 🕴

With GDPR enacted and the California Consumer Privacy Act on the near horizon, companies have to sharpen up their responses. Start by asking these six questions.

📖 Read

via "Dark Reading: ".
🔐 What's powering the unlikely rise of the millionaire hacker? 🔐

Six hackers made over $1 million this year for squashing security bugs, yet just five years ago this possibility seemed remote at best.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2010-5333

The web server in Integard Pro and Home before 2.0.0.9037 and 2.2.x before 2.2.0.9037 has a buffer overflow via a long password in an administration login POST request, leading to arbitrary code execution.

📖 Read

via "National Vulnerability Database".
🕴 US Sanctions 3 Cyber Attack Groups Tied to DPRK 🕴

Lazarus Group, Bluenoroff, and Andariel were named and sanctioned by the US Treasury for ongoing attacks on financial systems.

📖 Read

via "Dark Reading: ".
iPhone iOS 13 Lockscreen Bypass Flaw Exposes Contacts

Apple will not fix the glitch until the release of iOS 13.1 later in September.

📖 Read

via "Threatpost".
🔐 Cybercriminals shop for admin access to healthcare portals 🔐

Administrator access to backend systems is becoming the holy grail for attackers.

📖 Read

via "Security on TechRepublic".
🔏 New Principles for Maintaining Health Information Privacy Outlined 🔏

There's a fresh new slate of industry privacy guidelines for companies that handle health and wellness data to follow.

📖 Read

via "Subscriber Blog RSS Feed ".
🕴 Malware Linked to Ryuk Targets Financial & Military Data 🕴

A newly discovered campaign, packing traces of Ryuk ransomware, aims to steal confidential information.

📖 Read

via "Dark Reading: ".
WordPress XSS Bug Allows Drive-By Code Execution

Sites that use the Gutenberg (found in WordPress 5.0 to 5.2.2) are open to complete takeover.

📖 Read

via "Threatpost".