🛡 Cybersecurity & Privacy 🛡 - News
25.9K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
ATENTION New - CVE-2012-5686

ZPanel 10.0.1 has insufficient entropy for its password reset process.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2012-5618

Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-4937

Joomla! 1.7.1 has core information disclosure due to inadequate error checking.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-4912

Joomla! com_mailto 1.5.x through 1.5.13 has an automated mail timeout bypass.

📖 Read

via "National Vulnerability Database".
ATENTION New - CVE-2011-3629

Joomla! core 1.7.1 allows information disclosure due to weak encryption

📖 Read

via "National Vulnerability Database".
🕴 Kubernetes Shows Built-in Weakness 🕴

A Shmoocon presentation points out several weaknesses built in to Kubernetes configurations and how a researcher can exploit them.

📖 Read

via "Dark Reading: ".
🕴 Twitter Suspends Fake Accounts Abusing Feature that Matches Phone Numbers and Users 🕴

The company believes state-sponsored actors may also be involved.

📖 Read

via "Dark Reading: ".
🕴 7 Ways SMBs Can Secure Their Websites 🕴

Here's what small and midsize businesses should consider when they decide it's time to up their website security.

📖 Read

via "Dark Reading: ".
Medtronic Patches Implanted Device, CareLink Programmer Bugs

The medical device giant has issued fixes for bugs first disclosed in 2018 and 2019.

📖 Read

via "Threatpost".
Two Critical Android Bugs Get Patched in February Update

As part of its February bug fixes, Google is patching a critical severity remote code execution vulnerability and an information disclosure bug.

📖 Read

via "Threatpost".
🕴 Ransomware Attacks: Why It Should Be Illegal to Pay the Ransom 🕴

For cities, states and towns, paying up is short-sighted and only makes the problem worse.

📖 Read

via "Dark Reading: ".
🔏 HHS Issues Coronavirus HIPAA Guidance 🔏

In the healthcare sector, concerns about the spreading coronavirus outbreak have reignited the discussion around HIPAA, protected health information, and when it's legal for healthcare providers to disclose patient records.

📖 Read

via "Subscriber Blog RSS Feed ".
🔐 Why many security pros lack confidence in their implementation of Zero Trust 🔐

Almost half of security professionals don't know where or how to use Zero Trust policies in a hybrid IT environment, says a survey commissioned by security provider Pulse Secure.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 How to sign up for Firefox breach alerts 🔐

Mozilla offers users a service that will send alerts for account breaches associated with email addresses. Find out how to use Firefox Monitor.

📖 Read

via "Security on TechRepublic".
🔐 Untested app and no training for volunteers are fatal in Iowa caucus 🔐

HR experts and tech leaders say organizations that skip training during a tech transition almost always pay a high price.

📖 Read

via "Security on TechRepublic".
Ransomware Attack Hinders Toll Group Operations

Customers took to Twitter to air their grievances after some of the transportation giant's operations were downed.

📖 Read

via "Threatpost".
🕴 Microsoft DART Finds Web Shell Threat on the Rise 🕴

Various APT groups are successfully using Web shell attacks on a more frequent basis.

📖 Read

via "Dark Reading: ".
Community Housing Nonprofit Hit with $1.2M Loss in BEC Scam

Red Kite said that domain-spoofing and convincing scam emails claiming to be from suppliers were the cause.

📖 Read

via "Threatpost".
🕴 SharePoint Bug Proves Popular Weapon for Nation-State Attacks 🕴

Thousands of servers could be exposed to SharePoint vulnerability CVE-2019-0604, recently used in cyberattacks against Middle East government targets.

📖 Read

via "Dark Reading: ".
🕴 8 of the 10 Most Exploited Bugs Last Year Involved Microsoft Products 🕴

Six of them were the same as from the previous year, according to new Recorded Future analysis.

📖 Read

via "Dark Reading: ".