πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
ATENTIONβ€Ό New - CVE-2012-4381

MediaWiki before 1.18.5, and 1.19.x before 1.19.2 saves passwords in the local database, (1) which could make it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack or, (2) when an authentication plugin returns a false in the strict function, could allow remote attackers to use old passwords for non-existing accounts in an external authentication system via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-4029

Cross-site scripting (XSS) vulnerability in main/dropbox/index.php in Chamilo LMS before 1.8.8.6 allows remote attackers to inject arbitrary web script or HTML via the category_name parameter in an addsentcategory action.

πŸ“– Read

via "National Vulnerability Database".
⚠ Monday review – the hot 23 stories of the week ⚠

From Google's OpenSK project to Apple's SMS 2FA proposal, and everything in between. Get up to date with the hot stories of the last week.

πŸ“– Read

via "Naked Security".
⚠ Frustrated author cybersquats novelist’s website ⚠

If you visit the website of renowned Canadian novelist Patrick deWitt today, you'll see a surprising message. "THIS IS NOT PATRICK DEWITT", it says.

πŸ“– Read

via "Naked Security".
⚠ FBI director warns of sustained Russian disinformation threat ⚠

Russia is still using social media in a sustained campaign to dabble in US affairs, according to FBI director Chris Wray.

πŸ“– Read

via "Naked Security".
⚠ Facebook encrypted messaging will β€˜create hiding places for child abuse’ ⚠

Child safety groups penned an open letter to Facebook, urging a delay on encrypted messaging until sufficient safeguards are in place.

πŸ“– Read

via "Naked Security".
⚠ Google Chrome to start blocking downloads served via HTTP ⚠

Google has announced a timetable for phasing out insecure file downloads in the Chrome browser starting with desktop version 81 due next month.

πŸ“– Read

via "Naked Security".
πŸ•΄ Day in the Life of a Bot πŸ•΄

A typical workday for a bot, from its own point of view.

πŸ“– Read

via "Dark Reading: ".
❌ Emotet Now Hacks Nearby Wi-Fi Networks to Spread Like a Worm ❌

The new tactic used by Emotet allows the malware to infect nearby insecure Wi-Fi networks - and their devices - via brute force loops.

πŸ“– Read

via "Threatpost".
❌ Docker Registries Expose Hundreds of Orgs to Malware, Data Theft ❌

Misconfigured Docker registries could leak confidential data, lead to a full-scale compromise and interrupt the business operations.”

πŸ“– Read

via "Threatpost".
πŸ•΄ 6 Factors That Raise The Stakes For IoT Security πŸ•΄

Developments that exacerbate the risk and complicate making Internet of Things devices more secure.

πŸ“– Read

via "Dark Reading: ".
πŸ•΄ Unlocked S3 Bucket Lets 36,077 Prison Files Escape πŸ•΄

The leaky repository belongs to JailCore, a cloud management and compliance platform used in several states' correctional facilities.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2012-5828

BlackBerry PlayBook before 2.1 has an Information Disclosure Vulnerability via a Web browser component error

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-2204

InfoSphere Guardium aix_ktap module: DoS

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-1994

HP Systems Insight Manager before 7.0 allows a remote user on adjacent network to access information

πŸ“– Read

via "National Vulnerability Database".
❌ Equifax Breach: Four Members of Chinese Military Charged with Hacking ❌

Feds have charged four members of the Chinese People’s Liberation Army (PLA) in connection with the infamous 2017 Equifax breach.

πŸ“– Read

via "Threatpost".
πŸ” Global shipping industry attacked by coronavirus-themed malware πŸ”

Hackers are using malicious emails about the coronavirus to trick people with a malware called AZORult.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Unlocked S3 Bucket Lets 36,077 Jail Files Escape πŸ•΄

The leaky repository belongs to JailCore, a cloud management and compliance platform used in several states' correctional facilities.

πŸ“– Read

via "Dark Reading: ".
πŸ” 13 tips to avoid Valentine's Day online romance scams πŸ”

Scammers use dating sites to try to build relationships with people to get money or personal information. Here are 13 tips to protect yourself.

πŸ“– Read

via "Security on TechRepublic".
πŸ” How some presidential campaigns use DMARC to protect their domains from being spoofed πŸ”

DMARC can prevent spammers from using a trusted domain name to send junk mail, a useful tactic for the presidential campaigns and for your organization, according to security provider Valimail.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ China's Military Behind 2017 Equifax Breach: DoJ πŸ•΄

Four members of China's People Liberation Army hacked the information broker, leading to the theft of sensitive data on approximately 145 million citizens.

πŸ“– Read

via "Dark Reading: ".