πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Firmware Weaknesses Can Turn Computer Subsystems into Trojans πŸ•΄

Network cards, video cameras, and graphics adapters are a few of the subsystems whose lack of security could allow attackers to turn them into spy implants.

πŸ“– Read

via "Dark Reading: ".
πŸ” Mac attacks on the rise πŸ”

Cyberattacks on Mac endpoints nearly doubled over those on Windows for the first time, according to the 2020 State of Malware Report.

πŸ“– Read

via "Security on TechRepublic".
πŸ›  Lulzbuster 1.2.0 πŸ› 

Lulzbuster is a very fast and smart web directory and file enumeration tool written in C.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
πŸ›  OpenDNSSEC 2.1.6 πŸ› 

OpenDNSSEC is software that manages the security of domain names on the Internet. The project intends to drive adoption of Domain Name System Security Extensions (DNSSEC) to further enhance Internet security.

πŸ“– Go!

via "Security Tool Files β‰ˆ Packet Storm".
ATENTIONβ€Ό New - CVE-2013-5594

Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4454

WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ 1.7M Nedbank Customers Affected via Third-Party Breach πŸ•΄

A vulnerability in the network of marketing contractor Computer Facilities led to a breach at the South African bank.

πŸ“– Read

via "Dark Reading: ".
❌ Active Exploits Hit Vulnerable WordPress ThemeGrill Plugin ❌

Websites using a vulnerable version of the WordPress plugin, ThemeGrill Demo Importer, are being targeted by attackers.

πŸ“– Read

via "Threatpost".
ATENTIONβ€Ό New - CVE-2013-4227

Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x before 7.x-1.11 for Drupal allows remote attackers to hijack the authentication of aribitrary users via a security token that is not a string data type.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Cyber Fitness Takes More Than a Gym Membership & a Crash Diet πŸ•΄

Make cybersecurity your top priority, moving away from addressing individual problems with Band-Aids and toward attaining a long-term cyber-fitness plan.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-6295

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2679

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-0718

IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5146

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Is your firmware vulnerable to attack? A report says it might be πŸ”

Unsigned firmware in WiFi adapters, USB hubs, trackpads, and other devices can be compromised by hackers, says enterprise firmware security company Eclypsium in a new report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Lumu to Emerge from Stealth at RSAC πŸ•΄

The new company will focus on giving customers earlier indications of network and server compromise.

πŸ“– Read

via "Dark Reading: ".
❌ Iran-Backed APTs Collaborate on 3-Year β€˜Fox Kitten’ Global Spy Campaign ❌

APT34/OilRig and APT33/Elfin have established a highly developed and persistent infrastructure that could be converted to distribute destructive wiper malware.

πŸ“– Read

via "Threatpost".
πŸ” Finally, the world is getting concerned about data privacy πŸ”

Consumers and employees are finally becoming more sensitive to the privacy of their data. As technology leaders it's worth getting ahead of this trend.

πŸ“– Read

via "Security on TechRepublic".
❌ Ring Mandates 2FA After Rash of Hacks ❌

Ring outlined new security and data privacy measures, Tuesday, following backlash of the connected doorbell in the past year.

πŸ“– Read

via "Threatpost".
πŸ” Washington Privacy Act Clears Senate πŸ”

Like other recent state data privacy laws, new legislation in Washington would require businesses to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

πŸ“– Read

via "Subscriber Blog RSS Feed ".