πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
❌ New Muhstik Botnet Attacks Target Tomato Routers ❌

Palo Alto Networks’ Unit 42 researchers observed a variant of the wormlike botnet that adds scanner technology to brute-force Web authentication.

πŸ“– Read

via "Threatpost".
πŸ•΄ Cybersecurity Lessons Learned from 'The Rise of Skywalker' πŸ•΄

They're especially relevant regarding several issues we face now, including biometrics, secure data management, and human error with passwords.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-4943

ImpressPages CMS v1.0.12 has Unspecified Remote Code Execution (fixed in v1.0.13)

πŸ“– Read

via "National Vulnerability Database".
πŸ” Email malware targets U.S. senator and military πŸ”

The cybercriminals behind the powerful banking malware have turned their attention to government targets like Sen. Cory Booker.

πŸ“– Read

via "Security on TechRepublic".
❌ Microsoft Leaves 250M Customer Service Records Open to the Web ❌

The trove of information is potentially a scammer's bonanza.

πŸ“– Read

via "Threatpost".
❌ sLoad Malware Revamped as Powerful β€˜StarsLord’ Loader ❌

The newest version of the sLoad malware dropper comes equipped with infection tracking capabilities and an anti-analysis trick.

πŸ“– Read

via "Threatpost".
πŸ›  Logwatch 7.5.3 πŸ› 

Logwatch analyzes and reports on unix system logs. It is a customizable and pluggable log monitoring system which will go through the logs for a given period of time and make a customizable report. It should work right out of the package on most systems.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ•΄ Startup Privafy Raises $22M with New Approach to Network Security πŸ•΄

The company today disclosed an approach to data security designed to protect against modern threats at a lower cost than complex network tools.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2011-3610

A Cross-site Scripting (XSS) vulnerability exists in the Serendipity freetag plugin before 3.30 in the tagcloud parameter to plugins/serendipity_event_freetag/tagcloud.swf.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3595

Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3582

A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.

πŸ“– Read

via "National Vulnerability Database".
⚠ Big Microsoft data breach – 250 million records exposed ⚠

Microsoft has today announced a data breach that affected one of its customer databases.

πŸ“– Read

via "Naked Security".
πŸ” Analysts question whether FBI election cybersecurity changes are robust enough πŸ”

New guidelines show how the agency will coordinate with state officials in the event of a cyberattack on election infrastructure.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ 'We Only Have Two of the Blinky Boxes Left to Go' πŸ•΄

Exactly who is king of the castle here?

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Why DPOs and CISOs Must Work Closely Together πŸ•΄

Recent data protection laws mean that the data protection officer and CISO must work in tandem to make sure users' data is protected.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Configuration Error Reveals 250 Million Microsoft Support Records πŸ•΄

Some the records, found on five identically configured servers, might have contained data in clear text.

πŸ“– Read

via "Dark Reading: ".
πŸ” NIST Issues Version 1.0 of Privacy Framework πŸ”

NIST released new guidance last week, its Privacy Framework, that can be used by organizations as a risk management tool, to answer questions about its privacy posture, or establish its own program.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2011-3621

A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3614

An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-3613

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

πŸ“– Read

via "National Vulnerability Database".