πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ” Shattering myths and misperceptions about biometric debit and credit cards πŸ”

Biometric cards could make a strong dent against credit card fraud, but several myths surround the technology.

πŸ“– Read

via "Security on TechRepublic".
❌ No β€˜Silver Bullet’ Fix for Alexa, Google Smart Speaker Hacks ❌

Karsten Nohl, who was behind this week's research that outlined new eavesdropping hacks for Alexa and Google Home, says that privacy for smart home assistants still has a ways to go.

πŸ“– Read

via "Threatpost".
πŸ•΄ Autoclerk Database Spills 179GB of Customer, US Government Data πŸ•΄

An open Elasticsearch database exposed hundreds of thousands of hotel booking reservations, compromising data from full names to room numbers.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ NordVPN Breached Via Data Center Provider's Error πŸ•΄

The VPN company said that one of its 3,000 servers in a third-party data center was open to exploitation through a misconfigured management tool.

πŸ“– Read

via "Dark Reading: ".
πŸ” Lack of Controls, User Negligence Exposed PII of Veterans πŸ”

A recent VA inspector general report discovered veterans' medical records among a cache of data left exposed on shared drives.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2017-8087

Information Leakage in PPPoE Packet Padding in AVM Fritz!Box 7490 with Firmware versions Fritz!OS 6.80 and 6.83 allows physically proximate attackers to view slices of previously transmitted packets or portions of memory via via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ The AI (R)evolution: Why Humans Will Always Have a Place in the SOC πŸ•΄

In cybersecurity, the combination of men, women and machines can do what neither can do alone -- form a complementary team capable of upholding order and fighting the forces of evil.

πŸ“– Read

via "Dark Reading: ".
❌ Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing ❌

The Qode Instagram Widget and Qode Twitter Feed both have bugs that could allow redirects to malicious sites.

πŸ“– Read

via "Threatpost".
❌ FTC Cracks Down on Stalkerware With Retina-X App Bans ❌

The FTC has banned the sale of three apps - marketed to monitor children and employees - unless the developers can prove that the apps will be used for legitimate purposes.

πŸ“– Read

via "Threatpost".
πŸ•΄ FIDO-Based Authentication Arrives for Smartwatches πŸ•΄

The Nok Nok App SDK for Smart Watch is designed to let businesses implement FIDO-based authentication on smartwatches.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9500

The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9499

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9498

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9497

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9496

The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9495

The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9494

The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9493

The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Alliance Forms to Focus on Securing Operational Technology πŸ•΄

While mainly made up of vendors, the Operational Technology Cyber Security Alliance aims to offer security best practices for infrastructure operators and industrial partners.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ About 50% of Apps Are Accruing Unaddressed Vulnerabilities πŸ•΄

In rush to fix newly discovered security issues, developers are neglecting to address older ones, Veracode study finds.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9501

The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.

πŸ“– Read

via "National Vulnerability Database".