🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2011-3595

Multiple Cross-site Scripting (XSS) vulnerabilities exist in Joomla! through 1.7.0 in index.php in the search word, extension, asset, and author parameters.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3582

A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.

📖 Read

via "National Vulnerability Database".
Big Microsoft data breach – 250 million records exposed

Microsoft has today announced a data breach that affected one of its customer databases.

📖 Read

via "Naked Security".
🔐 Analysts question whether FBI election cybersecurity changes are robust enough 🔐

New guidelines show how the agency will coordinate with state officials in the event of a cyberattack on election infrastructure.

📖 Read

via "Security on TechRepublic".
🕴 'We Only Have Two of the Blinky Boxes Left to Go' 🕴

Exactly who is king of the castle here?

📖 Read

via "Dark Reading: ".
🕴 Why DPOs and CISOs Must Work Closely Together 🕴

Recent data protection laws mean that the data protection officer and CISO must work in tandem to make sure users' data is protected.

📖 Read

via "Dark Reading: ".
🕴 Configuration Error Reveals 250 Million Microsoft Support Records 🕴

Some the records, found on five identically configured servers, might have contained data in clear text.

📖 Read

via "Dark Reading: ".
🔏 NIST Issues Version 1.0 of Privacy Framework 🔏

NIST released new guidance last week, its Privacy Framework, that can be used by organizations as a risk management tool, to answer questions about its privacy posture, or establish its own program.

📖 Read

via "Subscriber Blog RSS Feed ".
ATENTION New - CVE-2011-3621

A reverse proxy issue exists in FluxBB before 1.4.7 when FORUM_BEHIND_REVERSE_PROXY is enabled.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3614

An Access Control vulnerability exists in the Facebook, Twitter, and Embedded plugins in Vanilla Forums before 2.0.17.9.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3613

An issue exists in Vanilla Forums before 2.0.17.9 due to the way cookies are handled.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3612

Cross-Site Request Forgery (CSRF) vulnerability exists in panel.php in UseBB before 1.0.12.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3611

A File Inclusion vulnerability exists in act parameter to admin.php in UseBB before 1.0.12.

📖 Read

via "National Vulnerability Database".
🕴 Eight Flaws in MSP Software Highlight Potential Ransomware Vector 🕴

An attack chain of vulnerabilities in ConnectWise's software for MSPs has similarities to some of the details of the August attack on Texas local and state agencies.

📖 Read

via "Dark Reading: ".
🔐 3 biggest threats cybersecurity professionals are facing in 2020 🔐

Organizations are moving toward next-generation cybersecurity solutions this year, but security fragmentation is a looming threat.

📖 Read

via "Security on TechRepublic".
🔐 How to disconnect devices and revoke app privileges from your Firefox cloud account 🔐

You'll be surprised at how many devices, apps, and services are associated with your Firefox cloud account. Find out how to remove them.

📖 Read

via "Security on TechRepublic".
ATENTION New - CVE-2011-3622

A Cross-Site Scripting (XSS) vulnerability exists in the admin login screen in Phorum before 5.2.18.

📖 Read

via "National Vulnerability Database".
🕴 To Avoid Disruption, Ransomware Victims Continue to Pay Up 🕴

For all the cautions against doing so, one-third of organizations in a Proofpoint survey said they paid their attackers after getting infected with ransomware.

📖 Read

via "Dark Reading: ".
Vivin Nets Thousands of Dollars Using Cryptomining Malware

A newly discovered threat actor named Vivin is raking in Monero from cryptomining malware, showing that this type of attack isn't going away anytime soon.

📖 Read

via "Threatpost".
🕴 For Mismanaged SOCs, The Price Is Not Right 🕴

New research finds security operations centers suffer high turnover and yield mediocre results for the investment they require.

📖 Read

via "Dark Reading: ".
Pwn2Own Miami Contestants Haul in $180K for Hacking ICS Equipment

The competition targets the systems that run critical infrastructure and more.

📖 Read

via "Threatpost".