πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25K subscribers
88.4K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-4810 β€Ό

The Responsive Pricing Table WordPress plugin before 5.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5601 β€Ό

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5771 β€Ό

Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined messages.Γ‚ Γ‚ This issue affects Proofpoint Enterprise Protection: from 8.20.0 before patch 4796, from 8.18.6 before patch 4795 and all other prior versions.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-5355 β€Ό

The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Steps to Follow to Comply With the SEC Cybersecurity Disclosure Rule πŸ•΄

Mandiant/Google Cloud’s Jill C. Tyson offers up timelines, checklists, and other guidance around enterprise-wide readiness to ensure compliance with the new rule.

πŸ“– Read

via "Dark Reading".
🦿 VMware Explore Barcelona 2023: Enhanced Private AI and Sovereign Cloud Services Announced 🦿

VMware's Private AI platform will include interoperability with Intel, IBM's watsonx and Kyndryl.

πŸ“– Read

via "Tech Republic".
🦿 IT Pros in Australian Crypto Need to Brace for Regulation 🦿

The Australian government is moving towards regulating cryptocurrency, with a focus on those involved in developing and maintaining crypto platforms.

πŸ“– Read

via "Tech Republic".
πŸ•΄ Identity Alone Won't Save Us: The TSA Paradigm and MGM's Hack πŸ•΄

To combat sophisticated threats, we need to improve how we approach authorization and access controls.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Atlassian Bug Escalated to 10, All Unpatched Instances Vulnerable πŸ•΄

Active ransomware attacks against vulnerable Atlassian Confluence Data Center and Servers ratchets up risk to enterprises, now reflected in the bug's revised CVSS score of 10.

πŸ“– Read

via "Dark Reading".
❀1πŸ‘1
🦿 Speedify Review 2023: Features, Security & Performance 🦿

Speedify VPN offers speed-centered features that may not make up for its lack of security and pricey plan. Find out how this VPN measured up in our review.

πŸ“– Read

via "Tech Republic".
πŸ•΄ North Korea's BlueNoroff APT Debuts 'Dumbed Down' macOS Malware πŸ•΄

Kim Jong-Un's hackers are scraping the bottom of the barrel, using script kiddie-grade malware to steal devalued digital assets.

πŸ“– Read

via "Dark Reading".
🦿 hide.me VPN Review 2023: Features, Pricing, and More 🦿

hide.me VPN is a secure and customizable solution. Read this comprehensive review to learn about its features, performance, pricing, and more.

πŸ“– Read

via "Tech Republic".
πŸ•΄ CVSS 4.0 Offers Significantly More Patching Context πŸ•΄

The latest vulnerability severity scoring system addresses gaps in the previous version; here's how to get the most out of it.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Marina Bay Sands Becomes Latest Hospitality Cyber Victim πŸ•΄

Unknown attackers have accessed PII for hundreds of thousands of loyalty customers at the high-end Singapore establishment.

πŸ“– Read

via "Dark Reading".
πŸ•΄ Malwarebytes Launches ThreatDown to Empower Resource Constrained IT Organizations πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ Risk Ledger Secures Β£6.25M to Prevent Cyberattacks on the Supply Chains of Nation's Largest Enterprises πŸ•΄



πŸ“– Read

via "Dark Reading".
πŸ•΄ Software Complexity Bedevils Mainframe Security πŸ•΄

The high-performance and resilient platforms satisfy critical roles, but software complexity and the graying of the specialist workforce are creating security challenges.

πŸ“– Read

via "Dark Reading".
🦿 Get 3 Years of Rock-Solid Protection With Surfshark VPN for $67.20 by 11/9 🦿

Find out more about why Surfshark VPN is a great choice for your digital privacy. Get advantage of this limited time offer by using code VPN20 at checkout.

πŸ“– Read

via "Tech Republic".
πŸ‘1πŸ€”1
πŸ•΄ CISOs Beware: SEC's SolarWinds Action Shows They're Scapegoating Us πŸ•΄

In a rapidly evolving cybersecurity landscape, CISOs must take proactive measures to safeguard their careers and mitigate risks associated with their roles.

πŸ“– Read

via "Dark Reading".
🦿 New SecuriDropper Malware Bypasses Android 13 Restrictions, Disguised as Legitimate Applications 🦿

A new malware is bypassing an Android 13 security measure that restricts permissions to apps downloaded out of the legitimate Google Play Store.

πŸ“– Read

via "Tech Republic".
πŸ”₯1