πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
26K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Cozy Bear Emerges from Hibernation to Hack EU Ministries πŸ•΄

The cyber-espionage group, linked to Russia and blamed for hacking the Democratic National Committee in 2016, has been using covert communications and other techniques to escape detection for at least two years.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9479 (acf_fronted_display)

The ACF-Frontend-Display plugin through 2015-07-03 for WordPress has arbitrary file upload via an action=upload request to js/blueimp-jQuery-File-Upload-d45deb1/server/php/index.php.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Yahoo Breach Victims May Qualify for $358 Payout πŸ•΄

Pending approval of the settlement, affected account holders may be eligible for a payout or two years of free credit monitoring.

πŸ“– Read

via "Dark Reading: ".
❌ Hacking Back? BriansClub Dark Web Attack a Boon for Banks ❌

The theft of 26 million card records from an underground site offers valuable intel for banks.

πŸ“– Read

via "Threatpost".
πŸ” 70 Percent of Healthcare Breach Data Could Lead to ID Theft πŸ”

New research looks at 10 years of healthcare data breaches and breaks down the specific types of data exposed.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ” How to find the Firefox Certificate Viewer πŸ”

Mozilla is set to launch a Certificate Viewer. Find out why and how to open it.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Smart Prevention: How Every Enterprise Can Create Human Firewalls πŸ•΄

Organizations of all sizes should include both human firewalls and virtual tools in their cybersecurity budgets.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to find the Firefox Certificate Viewer πŸ”

Mozilla is set to launch a Certificate Viewer. Find out why and how to open it.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2015-9482 (car_dealer_/_auto_dealer_responsive)

The ThemeMakers Car Dealer / Auto Dealer Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-5334 (webclient)

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ State of SMB Insecurity by the Numbers πŸ•΄

SMBs still perceive themselves at low risk from cyberthreats - in spite of attack statistics that paint a different picture.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Phishing Campaign Targets Stripe Credentials, Financial Data πŸ•΄

Attackers make use of an old trick and evade detection by blocking users from viewing an embedded link when hovering over the URL.

πŸ“– Read

via "Dark Reading: ".
πŸ” How to add public SSH keys for users in Cockpit πŸ”

Adding public SSH keys with Cockpit can easily be handled by a Cockpit admin.

πŸ“– Read

via "Security on TechRepublic".
❌ Phorpiex Botnet Shifts Gears From Ransomware to Sextortion ❌

A decade-old botnet is using infected computers to send out sextortion emails, in a wide-scale campaign with the potential to reach millions of victims.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9481 (diplomat_|_political)

The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to add public SSH keys for users in Cockpit πŸ”

Adding public SSH keys with Cockpit can easily be handled by a Cockpit admin.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Older Amazon Devices Subject to Old Wi-Fi Vulnerability πŸ•΄

The vulnerability in first-generation Echoes and eight-generation Kindles lets an attacker wage man-in-the-middle attacks.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Debug Feature in Web Dev Tool Exposed Trump Campaign Site, Others to Attack πŸ•΄

The problem is not with the tool itself but with how some developers and administrators are using it, Comparitech says.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9484 (accio_one_page_parallax_responsive_theme)

The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9483 (invento_responsive_gallery/architecture_template)

The ThemeMakers Invento Responsive Gallery/Architecture Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

πŸ“– Read

via "National Vulnerability Database".
⚠ Much-attacked Baltimore uses β€˜mind-bogglingly’ bad data storage ⚠

IT workers have been storing files on their computers' hard drives. One councilman's alleged response: β€œThat can’t be right? That’s real?”

πŸ“– Read

via "Naked Security".