πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Cyber Fitness Takes More Than a Gym Membership & a Crash Diet πŸ•΄

Make cybersecurity your top priority, moving away from addressing individual problems with Band-Aids and toward attaining a long-term cyber-fitness plan.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2013-6295

PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-3323

A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtain unauthorized access.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-2679

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2012-0718

IBM Tivoli Endpoint Manager 8 does not set the HttpOnly flag on cookies.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2009-5146

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“– Read

via "National Vulnerability Database".
πŸ” Is your firmware vulnerable to attack? A report says it might be πŸ”

Unsigned firmware in WiFi adapters, USB hubs, trackpads, and other devices can be compromised by hackers, says enterprise firmware security company Eclypsium in a new report.

πŸ“– Read

via "Security on TechRepublic".
πŸ•΄ Lumu to Emerge from Stealth at RSAC πŸ•΄

The new company will focus on giving customers earlier indications of network and server compromise.

πŸ“– Read

via "Dark Reading: ".
❌ Iran-Backed APTs Collaborate on 3-Year β€˜Fox Kitten’ Global Spy Campaign ❌

APT34/OilRig and APT33/Elfin have established a highly developed and persistent infrastructure that could be converted to distribute destructive wiper malware.

πŸ“– Read

via "Threatpost".
πŸ” Finally, the world is getting concerned about data privacy πŸ”

Consumers and employees are finally becoming more sensitive to the privacy of their data. As technology leaders it's worth getting ahead of this trend.

πŸ“– Read

via "Security on TechRepublic".
❌ Ring Mandates 2FA After Rash of Hacks ❌

Ring outlined new security and data privacy measures, Tuesday, following backlash of the connected doorbell in the past year.

πŸ“– Read

via "Threatpost".
πŸ” Washington Privacy Act Clears Senate πŸ”

Like other recent state data privacy laws, new legislation in Washington would require businesses to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

πŸ“– Read

via "Subscriber Blog RSS Feed ".
ATENTIONβ€Ό New - CVE-2013-4228

The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to private groups, which allows remote authenticated users to guess node IDs, subscribe to, and read the content of arbitrary private groups via unspecified vectors.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2013-4226

The Authenticated User Page Caching (Authcache) module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to cached pages, which allows remote attackers with the same role-combination as the superuser to obtain sensitive information via the cached pages of the superuser.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Dell Sells RSA to Private Equity Firm for $2.1B πŸ•΄

Deal with private equity entity Symphony Technology Group revealed one week before the security industry's RSA Conference in San Francisco.

πŸ“– Read

via "Dark Reading: ".
❌ FC Barcelona Suffers Likely Credential-Stuffing Attack on Twitter ❌

OurMine took over the Spanish powerhouse soccer team's Twitter account.

πŸ“– Read

via "Threatpost".
πŸ•΄ The Trouble with Free and Open Source Software πŸ•΄

Insecure developer accounts, legacy software, and nonstandard naming schemes are major problems, Linux Foundation and Harvard study concludes.

πŸ“– Read

via "Dark Reading: ".
ATENTIONβ€Ό New - CVE-2015-0749

A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user to follow a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information.

πŸ“– Read

via "National Vulnerability Database".
ATENTIONβ€Ό New - CVE-2011-2054

A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker must have the correct primary credentials in order to successfully exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
⚠ OpenSSH eases admin hassles with FIDO U2F token support ⚠

OpenSSH version 8.2 is out and the big news is that the world’s most popular remote management software now supports authentication using any FIDO (Fast Identity Online) U2F hardware token.

πŸ“– Read

via "Naked Security".
⚠ WordPress plugin hole could have allowed attackers to wipe websites ⚠

A WordPress plugin with over 100,000 active installations had a bug that could have allowed unauthorised attackers to wipe its users' blogs clean, it emerged this week.

πŸ“– Read

via "Naked Security".