πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2010-3782

obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.

πŸ“– Read

via "National Vulnerability Database".
πŸ” How to install and use git-secret πŸ”

Learn how to gain more security in your git repository with the help of the git-secret tool.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ CCPA Kickoff: What Businesses Need to Know πŸ•΄

The California Consumer Privacy Act is in full effect, prompting organizations to think about how they'll remain compliant.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Time for Insider-Threat Programs to Grow Up πŸ•΄

Immature programs attempting to protect against damaging attacks by insiders run the risk of alienating employees.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-1642

Multiple cross-site scripting (XSS) vulnerabilities in QuiXplorer before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) dir, (2) item, (3) order, (4) searchitem, (5) selitems[], or (6) srt parameter to index.php or (7) the QUERY_STRING to index.php.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-1420

Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/. NOTE: the path parameter in admin/upload.php vector is already covered by CVE-2012-6621.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-0737

Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter.

πŸ“– Read

via "National Vulnerability Database".
⚠ Python is dead. Long live Python! ⚠

Is Python 2 *really* dead. Or is it just shagged out after a long squawk?

πŸ“– Read

via "Naked Security".
❌ Google Boots Security Camera Maker From Nest Hub After Private Images Go Public ❌

The issue came to light after a Reddit user claimed being able to see strangers on his Xiaomi Mijia smart camera.

πŸ“– Read

via "Threatpost".
πŸ•΄ Organizations May 'Uncloud' Over Security, Budgetary Concerns πŸ•΄

While most cloud vendors forecast continued adoption and growth, some customers are taking a harder look at the cloud services they're using

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Continental Drift: Is Digital Sovereignty Splitting Global Data Centers? πŸ•΄

The recent proposal by Germany, backed by France, to fuse the infrastructures of Europe's cloud providers could challenge every data center storing a European's data.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Malware Hits Travelex Currency Exchange Service πŸ•΄

The New Year's Eve malware attack forced Travelex employees to resort to manual operations.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ The Edge Cartoon Caption Contest: Latest Winners, New Toon 'Like a Boss' πŸ•΄

Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.

πŸ“– Read

via "Dark Reading: ".
❌ Travelex Knocked Offline by System-Wide Malware Attack ❌

The foreign-currency-exchange giant said that it has been hit by a virus, affecting retail customers and banking partners alike.

πŸ“– Read

via "Threatpost".
πŸ” Friday Five: 1/3 Edition πŸ”

Ransomware takes down a USCG Maritime Facility, an email server belonging to the Special Olympics New York is hacked, and more - catch up on all the week's news with the Friday Five.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
⚠ Cryptocurrency exchange Poloniex issues password reset warning ⚠

Yes, there was a breach. But it's an old one that the crooks are trying to use again.

πŸ“– Read

via "Naked Security".
❌ Cybercriminals Fill Up on Gas Pump Transaction Scams Ahead of Oct. Deadline ❌

Gas stations will become liable for card-skimming at their pay-at-the-pump mechanisms starting in October.

πŸ“– Read

via "Threatpost".
❌ 3 Critical Bugs Allow Remote Attacks on Cisco NX-OS and Switches ❌

Cisco patched three authentication bypass bugs tied to its DCNM platform used to manages NX-OS.

πŸ“– Read

via "Threatpost".
❌ Ransomware Attack Topples Telemarketing Firm, Leaving Hundreds Jobless ❌

Days before Christmas, employees found out that The Heritage Company had been hit by a ransomware attack and was "temporarily suspending operations."

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2012-4451

Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.

πŸ“– Read

via "National Vulnerability Database".