πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ 5 Updates to PCI DSS That You Need to Know πŸ•΄

As payment technologies evolve, so do the requirements for securing cardholder data.

πŸ“– Read

via "Dark Reading: ".
πŸ” Digital Guardian Designated a Cyber Catalyst By Marsh πŸ”

Digital Guardian is excited to share that our Data Protection Platform has been designated a Cyber CatalystSM solution!

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Unpatched Bug Under Active Attack Threatens WordPress Sites with XSS ❌

The issue in the Rich Reviews plugin is being actively exploited.

πŸ“– Read

via "Threatpost".
πŸ” Latest research says organizations need to integrate security principles with DevOps πŸ”

The 2019 State of DevOps report found that teams at higher levels of DevOps evolution involved their security experts from the beginning.

πŸ“– Read

via "Security on TechRepublic".
❌ β€˜Narrator’ Windows Utility Trojanized to Gain Full System Control ❌

An active APT campaign aimed at tech companies is underway, which also uses a legitimate NVIDIA graphics function.

πŸ“– Read

via "Threatpost".
πŸ•΄ Long-Lining: Reeling In the Big Fish in Your Supply Chain πŸ•΄

The object of this new attack campaign is not swordfish or tuna but high-ranking executives within target organizations.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9409

The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cloud Insight ... and Stuff πŸ•΄

All fluff, all the time.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 5 Updates from PCI SSC That You Need to Know πŸ•΄

As payment technologies evolve, so do the requirements for securing cardholder data.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ When Compliance Isn't Enough: A Case for Integrated Risk Management πŸ•΄

Why governance, risk, and compliance solutions lull companies into a false sense of security, and how to form a more effective approach.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ GandCrab Developers Behind Destructive REvil Ransomware πŸ•΄

Code similarities show a definite technical link between the malware strains, Secureworks says.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ New Emergency Communications Plan Released by CISA πŸ•΄

The Cybersecurity and Infrastructure Security Agency's latest version of the National Emergency Communications Plan comes after a two-year process to improve the cybersecurity and flexibility of the nation's emergency communications.

πŸ“– Read

via "Dark Reading: ".
❌ Magecart Group Targets Routers Behind Public Wi-Fi Networks ❌

Magecart Group 5 has been spotted testing and preparing code to be injected onto commercial routers - potentially opening up guests connecting to Wi-Fi networks to payment data theft.

πŸ“– Read

via "Threatpost".
πŸ” Amazon's Echo, Alexa parade: What it all means πŸ”

Here are Larry Dignan's key takeaways from Amazon's 2019 hardware event and what it means for smart home integration, privacy, and digital assistants.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2015-9431

The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9430

The crazy-bone plugin before 0.6.0 for WordPress has XSS via the User-Agent HTTP header.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9429

The yith-maintenance-mode plugin before 1.2.0 for WordPress has CSRF with resultant XSS via the wp-admin/themes.php?page=yith-maintenance-mode panel_page parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9428

The wplegalpages plugin before 1.1 for WordPress has CSRF with resultant XSS via wp-admin/admin.php?page=legal-pages lp-domain-name, lp-business-name, lp-phone, lp-street, lp-city-state, lp-country, lp-email, lp-address, or lp-niche parameters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9427

The googmonify plugin through 0.5.1 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=googmonify.php PID or AID parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9426

The manual-image-crop plugin before 1.11 for WordPress has CSRF with resultant XSS via the wp-admin/admin-ajax.php?action=mic_editor_window postId parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9425

The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.

πŸ“– Read

via "National Vulnerability Database".