β Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing β
π Read
via "Threatpost".
The Qode Instagram Widget and Qode Twitter Feed both have bugs that could allow redirects to malicious sites.π Read
via "Threatpost".
Threat Post
Open Redirect Bug in Bridge Theme Plugin Opens Admins to Spearphishing
The Qode Instagram Widget and Qode Twitter Feed both have bugs that could allow redirects to malicious sites.
β FTC Cracks Down on Stalkerware With Retina-X App Bans β
π Read
via "Threatpost".
The FTC has banned the sale of three apps - marketed to monitor children and employees - unless the developers can prove that the apps will be used for legitimate purposes.π Read
via "Threatpost".
Threat Post
FTC Cracks Down on Stalkerware With Retina-X App Bans
The FTC has banned the sale of three apps - marketed to monitor children and employees - unless the developers can prove that the apps will be used for legitimate purposes.
π΄ FIDO-Based Authentication Arrives for Smartwatches π΄
π Read
via "Dark Reading: ".
The Nok Nok App SDK for Smart Watch is designed to let businesses implement FIDO-based authentication on smartwatches.π Read
via "Dark Reading: ".
Dark Reading
FIDO-Based Authentication Arrives for Smartwatches
The Nok Nok App SDK for Smart Watch is designed to let businesses implement FIDO-based authentication on smartwatches.
ATENTIONβΌ New - CVE-2015-9500
π Read
via "National Vulnerability Database".
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9499
π Read
via "National Vulnerability Database".
The Showbiz Pro plugin through 1.7.1 for WordPress has PHP code execution by uploading a .php file within a ZIP archive.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9498
π Read
via "National Vulnerability Database".
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9497
π Read
via "National Vulnerability Database".
The ad-inserter plugin before 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9496
π Read
via "National Vulnerability Database".
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9495
π Read
via "National Vulnerability Database".
The syndication-links plugin before 1.0.3 for WordPress has XSS via the genericons/example.html anchor identifier.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9494
π Read
via "National Vulnerability Database".
The indieweb-post-kinds plugin before 1.3.1.1 for WordPress has XSS via the genericons/example.html anchor identifier.π Read
via "National Vulnerability Database".
ATENTIONβΌ New - CVE-2015-9493
π Read
via "National Vulnerability Database".
The my-wish-list plugin before 1.4.2 for WordPress has multiple XSS issues.π Read
via "National Vulnerability Database".
π΄ Alliance Forms to Focus on Securing Operational Technology π΄
π Read
via "Dark Reading: ".
While mainly made up of vendors, the Operational Technology Cyber Security Alliance aims to offer security best practices for infrastructure operators and industrial partners.π Read
via "Dark Reading: ".
Dark Reading
Alliance Forms to Focus on Securing Operational Technology - Dark Reading
While mainly made up of vendors, the Operational Technology Cyber Security Alliance aims to offer security best practices for infrastructure operators and industrial partners.
π΄ About 50% of Apps Are Accruing Unaddressed Vulnerabilities π΄
π Read
via "Dark Reading: ".
In rush to fix newly discovered security issues, developers are neglecting to address older ones, Veracode study finds.π Read
via "Dark Reading: ".
Dark Reading
About 50% of Apps Are Accruing Unaddressed Vulnerabilities
In rush to fix newly discovered security issues, developers are neglecting to address older ones, Veracode study finds.
ATENTIONβΌ New - CVE-2015-9501
π Read
via "National Vulnerability Database".
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.π Read
via "National Vulnerability Database".
β Travel database exposed PII on US government employees β
π Read
via "Naked Security".
A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.π Read
via "Naked Security".
Naked Security
Travel database exposed PII on US government employees
A property management company owned by hotel chain Best Western has exposed 179 GB of sensitive travel information on thousands of travelers.
β 15 Years Later, Metasploit Still Manages to be a Menace β
π Read
via "Threatpost".
A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves, even against modern defenses.π Read
via "Threatpost".
Threat Post
15 Years Later, Metasploit Still Manages to be a Menace
A fresh look at the penetration testing tool Metasploit reveals the 15-year old hacking tool still has some tricks up its sleeves even against modern defenses.
β Facebook pulls fake news networks linked to Russia and Iran β
π Read
via "Naked Security".
It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.π Read
via "Naked Security".
Naked Security
Facebook pulls fake news networks linked to Russia and Iran
It took down four foreign interference campaigns and announced initiatives to prevent foreign interference in US elections.
β Hacker breached servers used by NordVPN β
π Read
via "Naked Security".
NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.π Read
via "Naked Security".
Naked Security
Hacker breached servers used by NordVPN
NordVPN has been forced to admit that a hacker stole an expired TLS certificate key used to securely connect customers to its web servers.
β Alexa and Google Home phishing apps demonstrated by researchers β
π Read
via "Naked Security".
The researchers' "Smart Spies" apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.π Read
via "Naked Security".
Naked Security
Alexa and Google Home phishing apps demonstrated by researchers
The researchersβ βSmart Spiesβ apps showed how Amazon Alexa and Google Home users could be exposed to vishing and eavesdropping.