🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2015-9499 (showbiz_pro)

The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.

📖 Read

via "National Vulnerability Database".
🕴 New: The 2019 Security Buyer's Guide 🕴

Whether you're a leader of a large enterprise or a smaller business, part of your ongoing security, risk management, and compliance strategy will be sourcing the most effective solution. This guide, sponsored by Akamai, will help you determine what to look for.

📖 Read

via "Dark Reading: ".
🔐 Gartner IT Symposium/Xpo 2019: The innovative thinking behind the IBM Garage 🔐

Blockchain, cloud and IoT are just a few of the tools being used within the IBM Garage to help clients innovate. The New York Times is using the IBM Garage to combat fake news by using blockchain.

📖 Read

via "Security on TechRepublic".
PHP Bug Allows Remote Code-Execution on NGINX Servers

CVE-2019-11043 is trivial to exploit -- and a proof of concept is available.

📖 Read

via "Threatpost".
ATENTION New - CVE-2010-4245

pootle 2.0.5-0.2 has XSS via 'match_names' parameter

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-4241

Tiki Wiki CMS Groupware 5.2 has CSRF

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-4240

Tiki Wiki CMS Groupware 5.2 has XSS

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-4239

Tiki Wiki CMS Groupware 5.2 has Local File Inclusion

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2010-3293

mailscanner can allow local users to prevent virus signatures from being updated

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2009-4900

pixelpost 1.7.1-5 has XSS

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2009-4899

pixelpost 1.7.1-5 has SQL injection

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2005-2349

Zoo 2.10-27 has Directory traversal

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2002-2444

Snoopy 2.0.0-1 has a security hole in exec cURL

📖 Read

via "National Vulnerability Database".
🕴 Database Error Exposes 7.5 Million Adobe Customer Records 🕴

The database was open for approximately one week before the problem was discovered.

📖 Read

via "Dark Reading: ".
🔏 Ex-SEC Employee Took Data to Land New Job 🔏

The DOJ says a former SEC examiner stole information from the government agency to help him land a chief compliance officer gig at a firm the SEC was investigating.

📖 Read

via "Subscriber Blog RSS Feed ".
🕴 US Lawmakers Fear Chinese-Owned TikTok Poses Security Risk 🕴

The popular video app has more than 110 million downloads in the United States and could give China access to users' personal data, they say.

📖 Read

via "Dark Reading: ".
Pwn2Own Expands Into Industrial Control Systems Hacking

White-hat hackers will now have the chance to win $20,000 for sniffing out remote code-execution flaws in industrial control systems.

📖 Read

via "Threatpost".
🔐 2020 predictions for technology, consumer packaged goods and retail 🔐

Nielsen released predictions for the next decade at the Gartner IT Symposium/Xpo 2019 and CPG and retail supply chains will need automation, blockchain and enhanced analytics to improve security.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2012-5577

Python keyring lib before 0.10 created keyring files with world-readable permissions.

📖 Read

via "National Vulnerability Database".
Adobe database exposes 7.5 million Creative Cloud users

Adobe has become the latest company to be caught leaving an Elasticsearch database full of customer data exposed on the internet.

📖 Read

via "Naked Security".
UniCredit Suffers Third Breach Despite Investing Billions in Cybersecurity

UniCredit was also hit with hacking incidents in September-October 2016 and June-July 2017.

📖 Read

via "Threatpost".