πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2015-5290

ircd-ratbox 3.0.9 mishandles the MONITOR command which allows remote attackers to cause a denial of service (system out-of-memory event).

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4318

File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2011

WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4420

An information disclosure flaw was found in the way the Java Virtual Machine (JVM) implementation of Java SE 7 as provided by OpenJDK 7 incorrectly initialized integer arrays after memory allocation (in certain circumstances they had nonzero elements right after the allocation). A remote attacker could use this flaw to obtain potentially sensitive information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-3462

A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux user context.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-3088

Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-3085

An authentication bypass exists in the web management interface in Belkin F5D8236-4 v2.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ How Should My Security Department Begin Future-Proofing for Quantum Computing? πŸ•΄

Knowing where your digital certificates are is just the start.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Two-Thirds of Security Pros Ready to or Already Volunteer Their Services πŸ•΄

Majority of survey respondents seek to share their security expertise with causes they care about.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Gauging the Cybersecurity Climate πŸ•΄

Is climate change impacting your cybersecurity, cyber-risk, or cyber-incident response plans?

πŸ“– Read

via "Dark Reading: ".
πŸ” How to protect specific folders and files in Windows πŸ”

Learn how to hide or encrypt specific files in Windows in order to better protect them.

πŸ“– Read

via "Security on TechRepublic".
πŸ” Security teams have a challenging and ever-changing role. Here's how a SOC can keep up πŸ”

Security teams should coordinate and operate by standard practices to ensure their efforts yield the maximum results. Learn some tips from an industry insider on how to make it happen.

πŸ“– Read

via "Security on TechRepublic".
❌ Facebook Security Debacles: 2019 Year in Review ❌

2019 was a tumultuous year for Facebook as it continued to grapple with privacy fallout after Cambridge Analytica, as well as dealing with a slew of security challenges.

πŸ“– Read

via "Threatpost".
πŸ•΄ Defensive Wish List for 2020: Faster Responses to Threats πŸ•΄

Security professionals recommend technology to detect attacks that have already infiltrated a network.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Poll Results: Security Pros Are Not Only Smart -- They're Generous, Too πŸ•΄

Altruism is alive and well among Edge readers, who seek to share their security expertise with causes they care about.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2014-4559

Multiple cross-site scripting (XSS) vulnerabilities in test-plugin.php in the Swipe Checkout for WP e-Commerce plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) api_key, (2) payment_page_url, (3) merchant_id, (4) api_url, or (5) currency parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-4525

Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in the Ebay Feeds for WordPress plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2014-4523

Cross-site scripting (XSS) vulnerability in the Easy Career Openings plugin 0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

πŸ“– Read

via "National Vulnerability Database".
❌ Google Chrome Affected By Magellan 2.0 Flaws ❌

Researchers warn that five vulnerabilities that stem from SQLite could enable remote code execution.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2016-1000029

Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).

πŸ“– Read

via "National Vulnerability Database".