πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-9501

The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.

πŸ“– Read

via "National Vulnerability Database".
⚠ Travel database exposed PII on US government employees ⚠

A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.

πŸ“– Read

via "Naked Security".
❌ 15 Years Later, Metasploit Still Manages to be a Menace ❌

A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves, even against modern defenses.

πŸ“– Read

via "Threatpost".
⚠ Facebook pulls fake news networks linked to Russia and Iran ⚠

It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.

πŸ“– Read

via "Naked Security".
⚠ Hacker breached servers used by NordVPN ⚠

NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.

πŸ“– Read

via "Naked Security".
⚠ Alexa and Google Home phishing apps demonstrated by researchers ⚠

The researchers' "Smart Spies" apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.

πŸ“– Read

via "Naked Security".
πŸ•΄ 8 Tips for More Secure Mobile Computing πŸ•΄

Mobile devices are a huge part of enterprise IT. Here's what to advise their users to do to keep their devices - and critical business data - best protected.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ What Has Cybersecurity Pros So Stressed -- And Why It's Everyone's Problem πŸ•΄

As cyberattacks intensify and the skills gap broadens, it's hard not to wonder how much more those in the industry can take before throwing in the towel.

πŸ“– Read

via "Dark Reading: ".
❌ Critical Firefox Bugs Allow Arbitrary Code-Execution ❌

Multiple critical memory safety bugs in Firefox 69 and Firefox ESR 68.1 in particular affect medium and large government entities and enterprises.

πŸ“– Read

via "Threatpost".
πŸ•΄ Report: 2020 Presidential Campaigns Still Vulnerable to Web Attacks πŸ•΄

Nine out of 12 Democratic candidates have yet to enable DNSSEC, a simple set of extensions that stops most targeted domain-based attacks.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ 10% of Small Businesses Breached Shut Down in 2019 πŸ•΄

As a result of cybercrime, 69% of small organizations were forced offline for a limited time and 37% experienced financial loss.

πŸ“– Read

via "Dark Reading: ".
❌ ThreatList: Google’s Advertising Network Dominates Global Data Collection ❌

With DoubleClick, Analytics and AdWords under its belt, Google continues dominating when it comes to global data collection for advertising, a new report found.

πŸ“– Read

via "Threatpost".
πŸ” Air Force Planning IP Protection Group Of Its Own πŸ”

To combat the ongoing epidemic around IP theft, the U.S. Air Force recently announced plans to develop an internal group to better protect the USAF's "hard-won intellectual property."

πŸ“– Read

via "Subscriber Blog RSS Feed ".
πŸ•΄ Planning a Zero-Trust Initiative? Here's How to Prioritize πŸ•΄

If you start by focusing on users, data, access, and managed devices, you will make major strides toward achieving better security.

πŸ“– Read

via "Dark Reading: ".
❌ Fujitsu Wireless Keyboard Plagued By Unpatched Flaws ❌

Two high-severity vulnerabilities in a Fujitsu wireless keyboard expose passwords and allow keystroke injection attacks.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9515

The Easy Digital Downloads (EDD) htaccess Editor extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9514

The Easy Digital Downloads (EDD) Free Downloads extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9513

The Easy Digital Downloads (EDD) Favorites extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2015-9512

The Easy Digital Downloads (EDD) CSV Manager extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

πŸ“– Read

via "National Vulnerability Database".