Urgent WordPress Update Fixes Critical Flaw in Jetpack Plugin on Million of Sites

Wed, 31 May 2023 18:54:00
0 minutes, 26 seconds
Dan

WordPress has issued an automatic update to address a critical flaw in the Jetpack plugin that's installed on over five million sites.

The vulnerability, which was unearthed during an internal security audit, resides in an API present in the plugin since version 2.0, which was released in November...

Critical Firmware Vulnerability in Gigabyte Systems Exposes ~7 Million Devices

Wed, 31 May 2023 18:52:00
0 minutes, 24 seconds
Dan

Cybersecurity researchers have found "backdoor-like behavior" within Gigabyte systems, which they say enables the UEFI firmware of the devices to drop a Windows executable and retrieve updates in an unsecure format.

Firmware security firm Eclypsium said it first detected the anomaly in April 2023....

LastPass Hack: Engineer's Failure to Update Plex Software Led to Massive Data Breach

Wed, 29 Mar 2023 19:37:00
1 minute, 4 seconds
Dan

The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what's a sobering reminder of the dangers of failing to keep software up-to-date.

The embattled password management service last week revealed how unidentified actors leveraged i...

Millions of Vehicles at Risk: API Vulnerabilities Uncovered in 16 Major Car Brands

Sat, 14 Jan 2023 22:03:00
0 minutes, 45 seconds
Dan

Millions of Vehicles at Risk: API Vulnerabilities Uncovered in 16 Major Car Brands

Multiple bugs affecting millions of vehicles from 16 different manufacturers could be abused to unlock, start, and track cars, plus impact the privacy of car owners.

The #security #vulnerabilities were found in th...

Hackers Exploit PrestaShop Zero-Day to Steal Payment Data from Online Stores

Malicious actors are exploiting a previously unknown security flaw in the open source PrestaShop e-commerce platform to inject malicious skimmer code designed to swipe sensitive information.

"Attackers have found a way to use a security vulnerability to carry out arbitrary code execution in server...