πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9458

The searchterms-tagging-2 plugin through 1.535 for WordPress has SQL injection via the pk_stt2_db_get_popular_terms count parameter exploitable via CSRF.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9457

The pretty-link plugin before 1.6.8 for WordPress has PrliLinksController::list_links SQL injection via the group parameter.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Works of Art: Cybersecurity Inspires 6 Winning Ideas πŸ•΄

The Center for Long Term Cybersecurity recently awarded grants to six artists in a contest to come up with ideas for works with security themes and elements. Check 'em out.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Akamai Snaps Up ChameleonX to Tackle Magecart πŸ•΄

The Israel-based ChameleonX aims to protect websites from cyberattacks targeting payment data.

πŸ“– Read

via "Dark Reading: ".
❌ Cryptomining Crook Steals Game Developer’s Identity to Carry Out Dirty Work ❌

An alleged fraudster built a vast web of AWS cloud accounts, becoming the platform's biggest consumer of data resources.

πŸ“– Read

via "Threatpost".
❌ vBulletin Flaw Exploited in Dutch Sex-Work Forum Breach ❌

A hacker is selling the email addresses of 250,000 users of a Dutch sex-work forum -- data that researchers say could be used for blackmail.

πŸ“– Read

via "Threatpost".
πŸ•΄ Imperva Details Response to Customer Database Exposure πŸ•΄

The cloud security's CEO and CTO lay out the timeline of events and the steps customers should take to protect their accounts.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ iTunes Zero-Day Exploited to Deliver BitPaymer πŸ•΄

The ransomware operators targeted an "unquoted path" vulnerability in iTunes for Windows to evade detection and install BitPaymer.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple removes app that tracks Hong Kong police and protestors ⚠

Apple was under fire this week after banning an app that tracked the location of both police and protesters in Hong Kong on a live map.

πŸ“– Read

via "Naked Security".
⚠ Facebook flags thousands of kids as interested in gambling, booze ⚠

According to a new report, its algorithmic labelling may expose minors to age-inappropriate, targeted advertising.

πŸ“– Read

via "Naked Security".
⚠ Hackers bypassing some types of 2FA security FBI warns ⚠

Some types of 2FA security can no longer be guaranteed to keep the bad guys out, the FBI warned US companies.

πŸ“– Read

via "Naked Security".
⚠ Most Americans don’t have a clue what https:// means ⚠

...and wouldn't know 2FA from a hole in the ground, according to Pew Research.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2010-5340

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5339

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5338

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5337

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5336

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5335

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5334

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
❌ Iran-Linked β€˜Charming Kitten’ Touts New Spearphishing Tactics ❌

A campaign first observed last year has ramped up its attack methods and appears to be linked to activity targeting President Trump’s 2020 re-election campaign.

πŸ“– Read

via "Threatpost".