πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9499

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9498

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9497

The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9496

The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9495

The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9494

The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9493

The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Alliance Forms to Focus on Securing Operational Technology πŸ•΄

While mainly made up of vendors, the Operational Technology Cyber Security Alliance aims to offer security best practices for infrastructure operators and industrial partners.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ About 50% of Apps Are Accruing Unaddressed Vulnerabilities πŸ•΄

In rush to fix newly discovered security issues, developers are neglecting to address older ones, Veracode study finds.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-9501

The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.

πŸ“– Read

via "National Vulnerability Database".
⚠ Travel database exposed PII on US government employees ⚠

A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.

πŸ“– Read

via "Naked Security".
❌ 15 Years Later, Metasploit Still Manages to be a Menace ❌

A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves, even against modern defenses.

πŸ“– Read

via "Threatpost".
⚠ Facebook pulls fake news networks linked to Russia and Iran ⚠

It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.

πŸ“– Read

via "Naked Security".
⚠ Hacker breached servers used by NordVPN ⚠

NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.

πŸ“– Read

via "Naked Security".
⚠ Alexa and Google Home phishing apps demonstrated by researchers ⚠

The researchers' "Smart Spies" apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.

πŸ“– Read

via "Naked Security".
πŸ•΄ 8 Tips for More Secure Mobile Computing πŸ•΄

Mobile devices are a huge part of enterprise IT. Here's what to advise their users to do to keep their devices - and critical business data - best protected.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ What Has Cybersecurity Pros So Stressed -- And Why It's Everyone's Problem πŸ•΄

As cyberattacks intensify and the skills gap broadens, it's hard not to wonder how much more those in the industry can take before throwing in the towel.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Firefox Bugs Allow Arbitrary Code-Execution ❌

Multiple critical memory safety bugs in Firefox 69 and Firefox ESR 68.1 in particular affect medium and large government entities and enterprises.

πŸ“– Read

via "Threatpost".
πŸ•΄ Report: 2020 Presidential Campaigns Still Vulnerable to Web Attacks πŸ•΄

Nine out of 12 Democratic candidates have yet to enable DNSSEC, a simple set of extensions that stops most targeted domain-based attacks.

πŸ“– Read

via "Dark Reading: ".