πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” New Principles for Maintaining Health Information Privacy Outlined πŸ”

There's a fresh new slate of industry privacy guidelines for companies that handle health and wellness data to follow.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Malware Linked to Ryuk Targets Financial & Military Data πŸ•΄

A newly discovered campaign, packing traces of Ryuk ransomware, aims to steal confidential information.

πŸ“– Read

via "Dark Reading: ".
❌ WordPress XSS Bug Allows Drive-By Code Execution ❌

Sites that use the Gutenberg (found in WordPress 5.0 to 5.2.2) are open to complete takeover.

πŸ“– Read

via "Threatpost".
⚠ Monday review – the hot 23 stories of the week ⚠

From Intel's SSH-stealing NetCAT bug to Mozilla's VPN - and everything in between. It's the weekly roundup.

πŸ“– Read

via "Naked Security".
⚠ Tiny Pacific nation forges ahead with national cryptocurrency ⚠

The Marshall Islands is facing rising seas and financial isolation. But critics say their get-rich-quick cryptocurrency scheme won't work.

πŸ“– Read

via "Naked Security".
⚠ Simjacker silent phone hack could affect a billion users ⚠

The shadowy world of phone-surveillance-for-hire became a little clearer last week following the discovery of a phone exploit called Simjacker.

πŸ“– Read

via "Naked Security".
⚠ Google fixes Chromebook 2FA flaw in β€˜built-in security key’ ⚠

Google has discovered a flaw in a Chromebook security feature which allows owners to press their device’s power button to initiate U2F 2FA.

πŸ“– Read

via "Naked Security".
⚠ iPhone lockscreen bypass: iOS 13 tricked into showing your contacts ⚠

This time, JosΓ© RodrΓ­guez came up with a way to trick the iOS 13 beta into showing its address book without the need to unlock the screen.

πŸ“– Read

via "Naked Security".
❌ New Threat Actor Fraudulently Buys Digital Certificates to Spread Malware ❌

ReversingLabs identified cybercriminals duping certificate authorities by impersonating legitimate entities and then selling the certificates on the black market.

πŸ“– Read

via "Threatpost".
πŸ•΄ Preventing PTSD and Burnout for Cybersecurity Professionals πŸ•΄

The safety of our digital lives is at stake, and we need to all do our part in raising awareness of these issues.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ US Sanctions 3 Cyber Attack Groups Tied to DPRK πŸ•΄

Lazarus Group, Bluenoroff, and Andariel were named and sanctioned by the US Treasury for ongoing attacks on financial systems.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2016-10966

The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10965

The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10964

The dwnldr plugin before 1.01 for WordPress has XSS via the User-Agent HTTP header.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10963

The icegram plugin before 1.9.19 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10962

The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10961

The colorway theme before 3.4.2 for WordPress has XSS via the contactName parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10960

The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php publish parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2016-10959

The estatik plugin before 2.3.1 for WordPress has authenticated arbitrary file upload (exploitable with CSRF) via es_media_images[] to wp-admin/admin-ajax.php.

πŸ“– Read

via "National Vulnerability Database".