🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2015-9508

The Easy Digital Downloads (EDD) Commissions extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9507

The Easy Digital Downloads (EDD) Attach Accounts to Orders extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9506

The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9505

The Easy Digital Downloads (EDD) core component 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7 for WordPress has XSS because add_query_arg is misused.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9504

The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9503

The Modern theme before 1.4.2 for WordPress has XSS via the genericons/example.html anchor identifier.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2015-9502

The Auberge theme before 1.4.5 for WordPress has XSS via the genericons/example.html anchor identifier.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2013-7333

A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from the SDN controller, causing degradation and eventually denial of network access to all devices connected to the targeted switch.

📖 Read

via "National Vulnerability Database".
🔐 Digital transformation: Why companies need a sense of urgency 🔐

TechRepublic's Karen Roby talks with futurist Brian Solis about the trends shaping digital transformation.

📖 Read

via "Security on TechRepublic".
🔐 Digital transformation: Why companies need a sense of urgency 🔐

TechRepublic's Karen Roby talks with futurist Brian Solis about the trends shaping digital transformation.

📖 Read

via "Security on TechRepublic".
🔐 Smart contracts and blockchain will provide needed trust, says Princeton professor 🔐

Princeton computer science professor Ed Felten says blockchain will enable smart contracts that provide trust to company systems in the future, but there are some myths and misconceptions.

📖 Read

via "Security on TechRepublic".
Bedside Hotel Robot Hacked to Stream In-Room Video

An unsecured NFC tag opens a door to trivial exploitation of robots inside Japanese hotels.

📖 Read

via "Threatpost".
🔐 Mobile malware increasingly being used for espionage by state-sponsored groups 🔐

State-sponsored groups take advantage of the lack of effective mobile malware solutions to target mobile users, according to a new report from BlackBerry.

📖 Read

via "Security on TechRepublic".
🔐 How to use RoboForm to manage and synchronize your browser bookmarks 🔐

RoboForm is more than a password manager--you can also use it as a tool for syncing your browser bookmarks.

📖 Read

via "Security on TechRepublic".
🕴 Oracle Releases Free Tool for Monitoring Internet Routing Security 🕴

IXP Filter Check gives Internet Exchange Points a way to verify whether they are properly filtering out incorrect and malicious routes.

📖 Read

via "Dark Reading: ".
🕴 Tough Choices 🕴

If you could only protect one category of your organization's data, what would it be?

📖 Read

via "Dark Reading: ".
ATENTION New - CVE-2014-2304

A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the controller service. This effect is the result of a flaw in OpenFlow protocol processing, where specific malformed and mistimed FEATURES_REPLY messages cause the controller service to not delete switch and port data from its internal tracking structures.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2002-2439

Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.

📖 Read

via "National Vulnerability Database".
🕴 IoTopia Framework Aims to Bring Security to Device Manufacturers 🕴

GlobalPlatform launches an initiative to help companies secure connected devices and services across markets.

📖 Read

via "Dark Reading: ".
🔐 Gartner IT Symposium/Xpo 2019: Security and regulatory concerns with public cloud 🔐

How IBM works with clients in regulated industries to scale AI across public clouds and protect data.

📖 Read

via "Security on TechRepublic".