πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing ❌

The Qode Instagram Widget and Qode Twitter Feed both have bugs that could allow redirects to malicious sites.

πŸ“– Read

via "Threatpost".
❌ FTC Cracks Down on Stalkerware With Retina-X App Bans ❌

The FTC has banned the sale of three apps - marketed to monitor children and employees - unless the developers can prove that the apps will be used for legitimate purposes.

πŸ“– Read

via "Threatpost".
πŸ•΄ FIDO-Based Authentication Arrives for Smartwatches πŸ•΄

The Nok Nok App SDK for Smart Watch is designed to let businesses implement FIDO-based authentication on smartwatches.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9500

The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9499

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9498

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9497

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9496

The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9495

The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9494

The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9493

The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Alliance Forms to Focus on Securing Operational Technology πŸ•΄

While mainly made up of vendors, the Operational Technology Cyber Security Alliance aims to offer security best practices for infrastructure operators and industrial partners.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ About 50% of Apps Are Accruing Unaddressed Vulnerabilities πŸ•΄

In rush to fix newly discovered security issues, developers are neglecting to address older ones, Veracode study finds.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9501

The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.

πŸ“– Read

via "National Vulnerability Database".
⚠ Travel database exposed PII on US government employees ⚠

A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.

πŸ“– Read

via "Naked Security".
❌ 15 Years Later, Metasploit Still Manages to be a Menace ❌

A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves, even against modern defenses.

πŸ“– Read

via "Threatpost".
⚠ Facebook pulls fake news networks linked to Russia and Iran ⚠

It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.

πŸ“– Read

via "Naked Security".
⚠ Hacker breached servers used by NordVPN ⚠

NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.

πŸ“– Read

via "Naked Security".
⚠ Alexa and Google Home phishing apps demonstrated by researchers ⚠

The researchers' "Smart Spies" apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.

πŸ“– Read

via "Naked Security".