ATENTIONβΌ New - CVE-2010-3782
π Read
via "National Vulnerability Database".
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.π Read
via "National Vulnerability Database".
π΄ Ransomware Scuttles Coast Guard Facility for 30+ Hours π΄
π Read
via "Dark Reading: ".
The attack on the unnamed facility began with a malicious email link.π Read
via "Dark Reading: ".
Dark Reading
Cyberattacks & Data Breaches recent news | Dark Reading
Explore the latest news and expert commentary on Cyberattacks & Data Breaches, brought to you by the editors of Dark Reading
π How to install and use git-secret π
π Read
via "Security on TechRepublic".
Learn how to gain more security in your git repository with the help of the git-secret tool.π Read
via "Security on TechRepublic".
TechRepublic
How to install and use git-secret
Learn how to gain more security in your git repository with the help of the git-secret tool.
π΄ CCPA Kickoff: What Businesses Need to Know π΄
π Read
via "Dark Reading: ".
The California Consumer Privacy Act is in full effect, prompting organizations to think about how they'll remain compliant.π Read
via "Dark Reading: ".
Dark Reading
CCPA Kickoff: What Businesses Need to Know
The California Consumer Privacy Act is in full effect, prompting organizations to think about how they'll remain compliant.
π΄ Time for Insider-Threat Programs to Grow Up π΄
π Read
via "Dark Reading: ".
Immature programs attempting to protect against damaging attacks by insiders run the risk of alienating employees.π Read
via "Dark Reading: ".
Dark Reading
Time for Insider-Threat Programs to Grow Up
Immature programs attempting to protect against damaging attacks by insiders run the risk of alienating employees.
ATENTIONβΌ New - CVE-2013-1642
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in QuiXplorer before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) dir, (2) item, (3) order, (4) searchitem, (5) selitems[], or (6) srt parameter to index.php or (7) the QUERY_STRING to index.php.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2013-1420
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to backup-edit.php; (2) title or (3) menu parameter to edit.php; or (4) path or (5) returnid parameter to filebrowser.php in admin/. NOTE: the path parameter in admin/upload.php vector is already covered by CVE-2012-6621.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2013-0737
π Read
via "National Vulnerability Database".
Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter.π Read
via "National Vulnerability Database".
β Python is dead. Long live Python! β
π Read
via "Naked Security".
Is Python 2 *really* dead. Or is it just shagged out after a long squawk?π Read
via "Naked Security".
Naked Security
Python is dead. Long live Python!
Is Python 2 *really* dead. Or is it just shagged out after a long squawk?
β Google Boots Security Camera Maker From Nest Hub After Private Images Go Public β
π Read
via "Threatpost".
The issue came to light after a Reddit user claimed being able to see strangers on his Xiaomi Mijia smart camera.π Read
via "Threatpost".
Threat Post
Google Boots Security Camera Maker From Nest Hub After Private Images Go Public
The issue came to light after a Reddit user claimed being able to see strangers on his Xiaomi Mijia smart camera.
π΄ Organizations May 'Uncloud' Over Security, Budgetary Concerns π΄
π Read
via "Dark Reading: ".
While most cloud vendors forecast continued adoption and growth, some customers are taking a harder look at the cloud services they're usingπ Read
via "Dark Reading: ".
Dark Reading
Organizations May 'Uncloud' Over Security, Budgetary Concerns
While most cloud vendors forecast continued adoption and growth, some customers are taking a harder look at the cloud services they're using
π΄ Continental Drift: Is Digital Sovereignty Splitting Global Data Centers? π΄
π Read
via "Dark Reading: ".
The recent proposal by Germany, backed by France, to fuse the infrastructures of Europe's cloud providers could challenge every data center storing a European's data.π Read
via "Dark Reading: ".
Dark Reading
Continental Drift: Is Digital Sovereignty Splitting Global Data Centers?
The recent proposal by Germany, backed by France, to fuse the infrastructures of Europe's cloud providers could challenge every data center storing a European's data.
π΄ Malware Hits Travelex Currency Exchange Service π΄
π Read
via "Dark Reading: ".
The New Year's Eve malware attack forced Travelex employees to resort to manual operations.π Read
via "Dark Reading: ".
Darkreading
Malware Hits Travelex Currency Exchange Service
The New Year's Eve malware attack forced Travelex employees to resort to manual operations.
π΄ The Edge Cartoon Caption Contest: Latest Winners, New Toon 'Like a Boss' π΄
π Read
via "Dark Reading: ".
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.π Read
via "Dark Reading: ".
Dark Reading
The Edge
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.
β Travelex Knocked Offline by System-Wide Malware Attack β
π Read
via "Threatpost".
The foreign-currency-exchange giant said that it has been hit by a virus, affecting retail customers and banking partners alike.π Read
via "Threatpost".
Threat Post
Travelex Knocked Offline by System-Wide Malware Attack
The foreign-currency-exchange giant said that it has been hit by a virus, affecting retail customers and banking partners alike.
π Friday Five: 1/3 Edition π
π Read
via "Subscriber Blog RSS Feed ".
Ransomware takes down a USCG Maritime Facility, an email server belonging to the Special Olympics New York is hacked, and more - catch up on all the week's news with the Friday Five.π Read
via "Subscriber Blog RSS Feed ".
Digital Guardian
Friday Five: 1/3 Edition
Ransomware takes down a USCG Maritime Facility, an email server belonging to the Special Olympics New York is hacked, and more - catch up on all the week's news with the Friday Five.
β Cryptocurrency exchange Poloniex issues password reset warning β
π Read
via "Naked Security".
Yes, there was a breach. But it's an old one that the crooks are trying to use again.π Read
via "Naked Security".
Naked Security
Cryptocurrency exchange Poloniex issues password reset warning
Yes, there was a breach. But itβs an old one that the crooks are trying to use again.
β Cybercriminals Fill Up on Gas Pump Transaction Scams Ahead of Oct. Deadline β
π Read
via "Threatpost".
Gas stations will become liable for card-skimming at their pay-at-the-pump mechanisms starting in October.π Read
via "Threatpost".
Threat Post
Cybercriminals Fill Up on Gas Pump Transaction Scams Ahead of Oct. Deadline
Gas stations will become liable for card-skimming at their pay-at-the-pump mechanisms starting in October.
β 3 Critical Bugs Allow Remote Attacks on Cisco NX-OS and Switches β
π Read
via "Threatpost".
Cisco patched three authentication bypass bugs tied to its DCNM platform used to manages NX-OS.π Read
via "Threatpost".
Threat Post
3 Critical Bugs Allow Remote Attacks on Cisco NX-OS and Switches
Cisco patched three authentication bypass bugs tied to its DCNM platform used to manages NX-OS.
β Ransomware Attack Topples Telemarketing Firm, Leaving Hundreds Jobless β
π Read
via "Threatpost".
Days before Christmas, employees found out that The Heritage Company had been hit by a ransomware attack and was "temporarily suspending operations."π Read
via "Threatpost".
Threat Post
Ransomware Attack Topples Telemarketing Firm, Leaving Hundreds Jobless
Days before Christmas, employees found out that The Heritage Company had been hit by a ransomware attack and was "temporarily suspending operations."
ATENTIONβΌ New - CVE-2012-4451
π Read
via "National Vulnerability Database".
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.π Read
via "National Vulnerability Database".