WordPress plug-in
WordPress Plugin Supply Chain Attack Gets Worse
Richi Jennings | | hacked WordPress, hacking wordpress, plug-in, plug-in vulnerability, plug-ins, rogue plug-in, SB Blogwatch, software supply chain, software supply chain attack, software supply chain attacks, software supply chain risk, Software Supply Chain risks, Supply-Chain Insecurity, Themes and Plug-ins, wordpress, WordPress plug-in, wordpress plugin update, Wordpress Plugin Vulnerability, WordPress Plugin Vulnerability Exploitation, WordPress Plugins, WordPress Plugins and Themes
30,000 websites at risk: Check yours ASAP! (800 Million Ostriches Can’t Be Wrong.) ...
Security Boulevard
Galaxy S9, iPhone X, Xiaomi Mi6 Devices Hacked at Pwn2Own Contest
Lucian Constantin | | AMP for WP, iphone x, mobile exploit, NFC hack, PWN2OWN, Samsung Galaxy S9, WordPress plug-in, Xiaomi Mi6
Two teams of hackers managed to break into the iPhone X, Samsung Galaxy S9 and Xiaomi Mi6 mobile devices at the mobile Pwn2Own contest held in Tokyo this week by using multiple ...
Security Boulevard
Hackers Exploit Critical Flaw in WordPress GDPR Compliance Plug-in
Lucian Constantin | | Privilege Escalation, VM escape, VMware, WordPress exploit, WordPress plug-in, WP GDPR Compliance
Hackers are breaking into WordPress websites by exploiting a recently patched privilege escalation vulnerability in a popular plug-in that allows site owners to conform to the GDPR user data collection requirements. The ...
Security Boulevard
Backdoors Found in Three More WordPress Plug-ins
Lucian Constantin | | Advertising, backdoor, password manager, SEO spam, software supply chain attack, user tracking, WordPress plug-in
In what is becoming an increasingly common type of software supply chain attack, three more WordPress plug-ins that recently changed ownership got backdoored by their new owners. What’s worse is that the malicious code ...
Security Boulevard
Oracle Patches Critical Vulnerabilities in PeopleSoft Applications
Lucian Constantin | | critical vulnerability, cross-site scripting, CVE-2017-10266, CVE-2017-10267, CVE-2017-10269, CVE-2017-10272, CVE-2017-10278, Duplicator, emergency update, Formidable Forms, Jolt protocol, JOLTandBLEED, Oracle PeopleSoft, Oracle Tuxedo, security patch, sql injection, WordPress plug-in, XSS, Yoast SEO
Oracle has released out-of-band security patches for a component used by multiple ERP applications from its PeopleSoft suite. The updates fix five vulnerabilities, including two critical ones that can be exploited to ...
Critical Dnsmasq Flaws Put Networking Devices, Linux Systems at Risk
Lucian Constantin | | Axiom, CCleaner, cyberespionage, Data breach, dnsmasq, Equifax, Linux, Malware, Remote Code Execution, router security, vulnerability, WordPress plug-in, zero-day
If you have Linux systems in your environment—desktops, servers, routers and other networking devices—you should install the latest patches for the dnsmasq package as soon as they become available. Security researchers from Google ...

