πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Cybercriminals using gifs to corrupt Drupal sites πŸ”

Hackers are taking advantage of vulnerabilities in the Drupal CMS platform by using malicious code disguised as gifs.

πŸ“– Read

via "Security on TechRepublic".
❌ Vulnerable Twitter API Leaves Tens of Thousands of iOS Apps Open to Attacks ❌

Millions of iOS users could be vulnerable to man-in-the-middle attacks that trace back to flawed Twitter code used in popular iPhone apps.

πŸ“– Read

via "Threatpost".
❌ California Bans Deepfakes in Elections, Porn ❌

A pair of laws provides recourse for victims of deepfake technology.

πŸ“– Read

via "Threatpost".
πŸ•΄ Drupalgeddon2 Vulnerability Still Endangering CMSes πŸ•΄

A new wave of attacks has been discovered on Drupal-based content management systems that weren't patched for the older flaw.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Lack of Role Models, Burnout & Pay Disparity Hold Women Back πŸ•΄

New ISACA data emphasizes a gap between men and women who share their opinions on underrepresentation of women and equal pay in the tech industry.

πŸ“– Read

via "Dark Reading: ".
⚠ Facebook’s Libra cryptocurrency dealt blow by PayPal’s departure ⚠

PayPal abruptly announced that it was leaving the Libra Association.

πŸ“– Read

via "Naked Security".
⚠ Nationwide facial recognition ID program underway in France ⚠

It's coming next month, in spite of a lawsuit and the data regulator's protests about lack of consent, data security and privacy.

πŸ“– Read

via "Naked Security".
⚠ GPS tracker from stalked woman’s car led to indictment of 20 mobsters ⚠

Girlfriend found it, girlfriend popped it onto a city bus, gadget got found, multiyear investigation got launched, 20 got indicted.

πŸ“– Read

via "Naked Security".
⚠ Signal immediately fixed FaceTime-style eavesdropping bug ⚠

Remember the FaceTime bug that allowed a caller to eavesdrop on your phone? Researchers just discovered another - this time in Signal.

πŸ“– Read

via "Naked Security".
πŸ•΄ Iranian Cyberattack on US Presidential Campaign Could Be a Sign of Things to Come πŸ•΄

Political parties and election systems will be heavily targeted in the months leading up to the 2020 general elections, some security experts say.

πŸ“– Read

via "Dark Reading: ".
❌ APT Groups Exploiting Flaws in Unpatched VPNs, Officials Warn ❌

U.S. and U.K. agencies warn consumers to update technologies from Fortinet, Pulse Secure and Palo Alto Networks to mitigate attacks that are likely coming from China

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9456

The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9455

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9454

The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9453

The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9452

The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9451

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9450

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Beyond the Horde: The Uptick in Targeted Attacks (And How to Fight Back) πŸ•΄

We're seeing a dramatic rise in targeted attacks, but following these guidelines can help your enterprise stay safe.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to build curl with SFTP support πŸ”

The curl package can be build to include SFTP support. Find out how easy this is to do.

πŸ“– Read

via "Security on TechRepublic".