πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2011-2934

A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2933

An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2715

An SQL Injection vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table names or column names.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2714

A Cross-Site Scripting vulnerability exists in Drupal 6.20 with Data 6.x-1.0-alpha14 due to insufficient sanitization of table descriptions, field names, or labels before display.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2706

A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.

πŸ“– Read

via "National Vulnerability Database".
❌ Oracle Ties Previous All-Time Patch High with January Updates ❌

The software giant patched 300+ bugs in its quarterly update.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cloud Adoption & Technology Change Create Gaps in Enterprise Security πŸ•΄

Many companies are struggling to get a handle on risk exposure because of visibility issues, Radware survey shows.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Microsoft Patches Windows Vuln Discovered by the NSA πŸ•΄

The National Security Agency is publicly acknowledged for its finding and reporting of CVE-2020-0601, marking the start of what it says is a new approach to security.

πŸ“– Read

via "Dark Reading: ".
⚠ Apple says no to unlocking shooter’s phone; AG and Trump lash back ⚠

Attorney General Barr and President Trump are demanding Apple unlock the mass shooter's iPhone. Apple replies: You can't break just 1 phone.

πŸ“– Read

via "Naked Security".
⚠ Peekaboo Moments baby-recording app has a bad database booboo ⚠

No need to wait until you've gurgled out of your mother's womb to experience the joys of having your privacy breached.

πŸ“– Read

via "Naked Security".
❌ Oski Data-Stealing Malware Emerges to Target North America, China ❌

The malware is new and in the early stages of its development -- but packs a sophisticated punch.

πŸ“– Read

via "Threatpost".
⚠ Malicious npm package taken down after Microsoft warning ⚠

Criminals have been caught trying to sneak a malicious package on to the popular Node.js platform npm (Node Package Manager).

πŸ“– Read

via "Naked Security".
⚠ Microsoft fixes critical bugs in CryptoAPI, RD Gateway and .NET ⚠

Here are the most serious bugs from Microsoft's Patch Tuesday - Including CryptoAPI and RCE flaws in Windows Remote Desktop Gateway.

πŸ“– Read

via "Naked Security".
πŸ” Why corporate boards are unprepared to handle cybersecurity risks πŸ”

A new report recommends that corporate boards answer four key questions on a regular basis to guide cybersecurity governance.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ How SD-WAN Helps Achieve Data Security and Threat Protection πŸ•΄

Enterprises currently consider the technology a best practice because of its flexibility, scalability, performance, and agility.

πŸ“– Read

via "Dark Reading: ".
πŸ” Microsoft rolls out patch for serious Windows bug highlighted by NSA πŸ”

Designed to exploit a vulnerability in Windows 10 and Windows Server 2016 and 2019, the bug could allow an attacker to remotely access and control an infected computer.

πŸ“– Read

via "Security on TechRepublic".
ATENTIONβ€Ό New - CVE-2012-1563

Joomla! before 2.5.3 allows Admin Account Creation.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1562

Joomla! core before 2.5.3 allows unauthorized password change.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1326

Cisco IronPort Web Security Appliance up to and including 7.5 does not validate the basic constraints of the certificate authority which could lead to MITM attacks

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1316

Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-0945

whoopsie-daisy before 0.1.26: Root user can remove arbitrary files

πŸ“– Read

via "National Vulnerability Database".