πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Microsoft Office Bug Remains Top Malware Delivery Vector πŸ•΄

CVE-2017-11882 has been attackers' favorite malware delivery mechanism throughout the second and third quarters of 2019.

πŸ“– Read

via "Dark Reading: ".
⚠ Crypto Capital boss arrested over money laundering ⚠

Bitfinex says the payment processor has $880M of the cryptocurrency exchange's β€œlost” funds. Polish authorities seized $390m of it.

πŸ“– Read

via "Naked Security".
❌ Cybercriminals Impersonate Russian APT β€˜Fancy Bear’ to Launch DDoS Attacks ❌

Attacks are targeting international companies in the financial sector, demanding that victims pay ransom in Bitcoin.

πŸ“– Read

via "Threatpost".
⚠ New BBC β€˜dark web’ Tor mirror site aims to beat censorship ⚠

A mirror copy of the BBC’s international news website is now available to users on the so-called dark web.

πŸ“– Read

via "Naked Security".
⚠ TikTok says no, senators, we’re not under China’s thumb ⚠

US lawmakers asked intelligence to look into whether the app and others like it could pose a security threat or be used to influence opinion.

πŸ“– Read

via "Naked Security".
⚠ Ransomware with a difference as hackers threaten to release city data ⚠

Johannesburg spent the weekend struggling to recover from its second malware attack this year as it took key services systems offline.

πŸ“– Read

via "Naked Security".
⚠ Monday review – the hot 21 stories of the week ⚠

Get yourself up to date with everything we've written in the last seven days - it's weekly roundup time.

πŸ“– Read

via "Naked Security".
πŸ•΄ 5 Things the Hoodie & the Hard Hat Need to Know About Each Other πŸ•΄

Traditionally, the worlds of IT (the hoodie) and OT (the hard hat) have been separate. That must change.

πŸ“– Read

via "Dark Reading: ".
❌ Magecart Gang Targets Skin Care Site Visitors For 5+ Months ❌

A Magecart skimmer, discovered on the site of First Aid Beauty, was only just removed after being in place for five months.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2015-9499 (showbiz_pro)

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ New: The 2019 Security Buyer's Guide πŸ•΄

Whether you're a leader of a large enterprise or a smaller business, part of your ongoing security, risk management, and compliance strategy will be sourcing the most effective solution. This guide, sponsored by Akamai, will help you determine what to look for.

πŸ“– Read

via "Dark Reading: ".
πŸ” Gartner IT Symposium/Xpo 2019: The innovative thinking behind the IBM Garage πŸ”

Blockchain, cloud and IoT are just a few of the tools being used within the IBM Garage to help clients innovate. The New York Times is using the IBM Garage to combat fake news by using blockchain.

πŸ“– Read

via "Security on TechRepublic".
❌ PHP Bug Allows Remote Code-Execution on NGINX Servers ❌

CVE-2019-11043 is trivial to exploit -- and a proof of concept is available.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2010-4245

pootle 2.0.5-0.2 has XSS via 'match_names' parameter

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4240

Tiki Wiki CMS Groupware 5.2 has XSS

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-4239

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2010-3293

mailscanner can allow local users to prevent virus signatures from being updated

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-4900

pixelpost 1.7.1-5 has XSS

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-4899

pixelpost 1.7.1-5 has SQL injection

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2005-2349

Zoo 2.10-27 has Directory traversal

πŸ“– Read

via "National Vulnerability Database".