πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9411

The Postmatic plugin before 1.4.6 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9411

The Postmatic plugin before 1.4.6 for WordPress has XSS.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9410

The Blubrry PowerPress Podcasting plugin 6.0.4 for WordPress has XSS via the tab parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Vimeo sued for storing faceprints of people without their say-so ⚠

The suit was filed under BIPA, the Illinois law that requires written consent to grab people's faceprints - the same law Facebook's battling.

πŸ“– Read

via "Naked Security".
⚠ Update ColdFusion now! Emergency patch for critical flaws ⚠

Adobe has rushed out fixes for three vulnerabilities in its ColdFusion web development platform, two of which have been given the top billing of β€˜critical’.

πŸ“– Read

via "Naked Security".
⚠ Russian pleads guilty in massive JPMorgan hacking scheme ⚠

Andrei Tyurin is the first to be convicted in one of the largest thefts of customer data from a single US financial institution in history.

πŸ“– Read

via "Naked Security".
⚠ Hackers are infecting WordPress sites via a defunct plug-in ⚠

If you're a Wordpress admin using a plug-in called Rich Reviews, you'll want to uninstall it. Now. The now-defunct plug-in has a major vulnerability that allows malvertisers to infect sites running Wordpress and redirect visitors to other sites.

πŸ“– Read

via "Naked Security".
❌ Chrome Bug, Not Avid Software, Causes Damage to MacOS File Systems ❌

Users scrambled to find a fix for the problem and eventually Google took responsibility for the issue.

πŸ“– Read

via "Threatpost".
❌ Cyber-Risk Business Cases: Using Economic Impact to Justify TIG Investment ❌

How to determine -- and communicate -- the value of Threat Intelligence Gateways (TIGs) in your enterprise.

πŸ“– Read

via "Threatpost".
πŸ” Why businesses would rather lose revenue than data πŸ”

While businesses don't want to lose data, 66% of business decision makers said their current IT resources do not keep up with growing technological demands.

πŸ“– Read

via "Security on TechRepublic".
⚠ S2 Ep10: Emotet’s back, mutant WannaCry and Insta scam – Naked Security Podcast ⚠

Here's the latest Naked Security podcast - listen now!

πŸ“– Read

via "Naked Security".
❌ CISOs: Support Vendor Security Ops for Best Cloud Results ❌

Despite CISOs' apprehension about increasing dependence on SaaS applications and the security risks the cloud represents, adoption isn’t slowing down.

πŸ“– Read

via "Threatpost".
πŸ” 75% of execs cite phishing as the most significant security threat to businesses πŸ”

Training is the key to helping the enterprise avoid cyber threats from phishing or other means.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Why You Need to Think About API Security πŸ•΄

Businesses of all sorts are increasingly relying on APIs to interact with customers in smartphone apps, but they have their own unique set of vulnerabilities.

πŸ“– Read

via "Dark Reading: ".
❌ Vimeo Slapped With Lawsuit Over Biometrics Privacy Policy ❌

Vimeo is under fire for allegedly collecting and storing users' facial biometrics in videos and photos without their consent or knowledge.

πŸ“– Read

via "Threatpost".
❌ Phish Uses Google’s URL Decoding to Swim Past Defenses ❌

Percentage-based URL encoding plus Google domain trickery is helping malicious emails to evade filters.

πŸ“– Read

via "Threatpost".
❌ Cisco Patches 13 High-Severity Router and Switch Bugs ❌

One Cisco bug impacting its 800 and 1000 series routers had a CVSS severity score of 9.9.

πŸ“– Read

via "Threatpost".
❌ 5G and IoT: How to Approach the Security Implications ❌

Experts from Nokia, iboss and Sectigo talk 5G mobile security for internet of things (IoT) devices in this webinar YouTube video (transcript included).

πŸ“– Read

via "Threatpost".
πŸ›  Falco 0.17.1 πŸ› 

Sysdig falco is a behavioral activity monitoring agent that is open source and comes with native support for containers. Falco lets you define highly granular rules to check for activities involving file and network activity, process execution, IPC, and much more, using a flexible syntax. Falco will notify you when these rules are violated. You can think about falco as a mix between snort, ossec and strace.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ” EU Court Limits 'Right to Be Forgotten' πŸ”

Google won what many viewed as a milestone case this week as Europe's top court ruled it doesn't have to extend the "right to be forgotten" privacy rule beyond the EU’s 28 states.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
❌ Rash of Exploits Targets Critical vBulletin RCE Bug ❌

After someone dropped a zero-day exploit on Securelist this week, the platform rushed out a fix -- time to apply it.

πŸ“– Read

via "Threatpost".