🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
🕴 Iranian Cyberattack on US Presidential Campaign Could Be a Sign of Things to Come 🕴

Political parties and election systems will be heavily targeted in the months leading up to the 2020 general elections, some security experts say.

📖 Read

via "Dark Reading: ".
APT Groups Exploiting Flaws in Unpatched VPNs, Officials Warn

U.S. and U.K. agencies warn consumers to update technologies from Fortinet, Pulse Secure and Palo Alto Networks to mitigate attacks that are likely coming from China

📖 Read

via "Threatpost".
ATENTION New - CVE-2015-9456

The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme_1_file, or theme_1_file_contents parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9455

The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9454

The smooth-slider plugin before 2.7 for WordPress has SQL Injection via the wp-admin/admin.php?page=smooth-slider-admin current_slider_id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9453

The broken-link-manager plugin before 0.6.0 for WordPress has XSS via the HTTP Referer or User-Agent header to a URL that does not exist.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9452

The nex-forms-express-wp-form-builder plugin before 4.6.1 for WordPress has SQL injection via the wp-admin/admin.php?page=nex-forms-main nex_forms_Id parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9451

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_mailchimp pmfb_tid parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9450

The plugmatter-optin-feature-box-lite plugin before 2.0.14 for WordPress has SQL injection via the wp-admin/admin-ajax.php?action=pmfb_cc pmfb_tid parameter.

📖 Read

via "National Vulnerability Database".
🕴 Beyond the Horde: The Uptick in Targeted Attacks (And How to Fight Back) 🕴

We're seeing a dramatic rise in targeted attacks, but following these guidelines can help your enterprise stay safe.

📖 Read

via "Dark Reading: ".
🔐 How to build curl with SFTP support 🔐

The curl package can be build to include SFTP support. Find out how easy this is to do.

📖 Read

via "Security on TechRepublic".
🔐 Cyberattacks are increasing, but AV and intrusion detection software are asleep at the wheel 🔐

Over three quarters of US businesses have faced cyberattacks in the past 12 months, with 86% of US firms experiencing attacks feeling let down by their antivirus.

📖 Read

via "Security on TechRepublic".
🔐 74% of global workers say the tech industry needs more regulation 🔐

The majority of workers worldwide think the tech industry needs more regulation, but the US in particular is falling behind.

📖 Read

via "Security on TechRepublic".
🔐 Robocalls annually scam one in 10 Americans, to a loss of $9.5 billion 🔐

Computerized auto dialers deliver pre-recorded phone calls with 60 billion expected in 2019 alone. Here's how to handle robocalls.

📖 Read

via "Security on TechRepublic".
🕴 7 Considerations Before Adopting Security Standards 🕴

Here's what to think through as you prepare your organization for standards compliance.

📖 Read

via "Dark Reading: ".
Google October Android Security Update Fixes Critical RCE Flaws

Google's October security update fixed several critical and high-severity vulnerabilities.

📖 Read

via "Threatpost".
🔐 How to build a better cybersecurity defense with deception technologies 🔐

This new cybersecurity defense mechanism proactively protects organizations and prevents attacks.

📖 Read

via "Security on TechRepublic".
🔐 How MIT researchers use machine learning to detect IP hijackings before it occurs 🔐

The goal is to predict incidents in advance by tracing it back to the actual hijackers.

📖 Read

via "Security on TechRepublic".
🔐 More companies use multi-factor authentication, but security still weak from poor password habits 🔐

Users still have to juggle far too many passwords, which leads to password sharing, reuse, and other bad habits, according to a new report from password manager LastPass.

📖 Read

via "Security on TechRepublic".
🕴 Business Email Compromise Attacks Spike 269% 🕴

A new Mimecast report finds a significant uptick in BEC attacks, malware attachments, and spam landing in target inboxes.

📖 Read

via "Dark Reading: ".
🔐 Only 1 in 5 enterprises have DMARC records set up with an enforcement policy 🔐

More companies than ever are adopting new email security methods, like DMARC, but few actually put them to full use.

📖 Read

via "Security on TechRepublic".