πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Akamai Snaps Up ChameleonX to Tackle Magecart πŸ•΄

The Israel-based ChameleonX aims to protect websites from cyberattacks targeting payment data.

πŸ“– Read

via "Dark Reading: ".
❌ Cryptomining Crook Steals Game Developer’s Identity to Carry Out Dirty Work ❌

An alleged fraudster built a vast web of AWS cloud accounts, becoming the platform's biggest consumer of data resources.

πŸ“– Read

via "Threatpost".
❌ vBulletin Flaw Exploited in Dutch Sex-Work Forum Breach ❌

A hacker is selling the email addresses of 250,000 users of a Dutch sex-work forum -- data that researchers say could be used for blackmail.

πŸ“– Read

via "Threatpost".
πŸ•΄ Imperva Details Response to Customer Database Exposure πŸ•΄

The cloud security's CEO and CTO lay out the timeline of events and the steps customers should take to protect their accounts.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ iTunes Zero-Day Exploited to Deliver BitPaymer πŸ•΄

The ransomware operators targeted an "unquoted path" vulnerability in iTunes for Windows to evade detection and install BitPaymer.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple removes app that tracks Hong Kong police and protestors ⚠

Apple was under fire this week after banning an app that tracked the location of both police and protesters in Hong Kong on a live map.

πŸ“– Read

via "Naked Security".
⚠ Facebook flags thousands of kids as interested in gambling, booze ⚠

According to a new report, its algorithmic labelling may expose minors to age-inappropriate, targeted advertising.

πŸ“– Read

via "Naked Security".
⚠ Hackers bypassing some types of 2FA security FBI warns ⚠

Some types of 2FA security can no longer be guaranteed to keep the bad guys out, the FBI warned US companies.

πŸ“– Read

via "Naked Security".
⚠ Most Americans don’t have a clue what https:// means ⚠

...and wouldn't know 2FA from a hole in the ground, according to Pew Research.

πŸ“– Read

via "Naked Security".
ATENTIONβ€Ό New - CVE-2010-5340

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5339

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5338

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5337

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5336

IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5335

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5334

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
❌ Iran-Linked β€˜Charming Kitten’ Touts New Spearphishing Tactics ❌

A campaign first observed last year has ramped up its attack methods and appears to be linked to activity targeting President Trump’s 2020 re-election campaign.

πŸ“– Read

via "Threatpost".
πŸ•΄ Close the Gap Between Cyber-Risk and Business Risk πŸ•΄

Four steps outlining how security teams can better understand their company's cyber-risk and demonstrate to company leadership what's being done to mitigate the resulting business risk.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Creative Wi-Fi Passwords πŸ•΄

Let's see a hacker figure out one of these.

πŸ“– Read

via "Dark Reading: ".
⚠ S2 Ep12: Dark Web, O.MG Cable spying and securing new laptops – Naked Security Podcast ⚠

Listen to the latest episode now!

πŸ“– Read

via "Naked Security".