Vulnerabilities
February 18, 2025
5 views 19 secs 0

Stealthy Malware in WordPress Sites Enables Remote Code Execution by Hackers

GBHackers reports that researchers have uncovered malware targeting WordPress websites, leveraging hidden backdoors to enable remote code execution (RCE): One notable case involved attackers embedding malicious scripts within the Must-Use Plugins (mu-plugins) directory, a special WordPress folder that automatically loads plugins on every page load without requiring activation. By placing obfuscated PHP code in this directory, attackers […]

Data Breach News, Cyberattack, Vulnerabilities
February 16, 2025
12 views 0 secs 0

China-linked APT Salt Typhoon has breached more U.S. telecommunications providers via unpatched Cisco IOS XE network devices.

Security Affairs reports: China-linked APT group Salt Typhoon is still targeting telecommunications providers worldwide, and according to a new report published by Recorded Future’s Insikt Group, the threat actors has breached more U.S. telecommunications providers by exploiting unpatched Cisco IOS XE network devices. Insikt Group researchers reported that the Chinese hacked have exploited two Cisco flaws, tracked […]

New Threats, Vulnerabilities
February 11, 2025
25 views 43 secs 0

Abandoned AWS Cloud Storage: A Major Cyberattack Vector

Everything old is exploitable again? DarkReading reports: Abandoned cloud storage buckets present a major, but largely overlooked, threat to Internet security, new research has shown. The risks arise when bad actors discover and re-register these neglected digital repositories under their original name, and then use them to deliver malware or carry out other malicious actions […]

Consumer Alerts, Vulnerabilities
February 05, 2025
33 views 11 secs 0

Android users must update their phones now over bugs that allow hackers to bypass passwords and hijack devices

Mobile phone owners are strongly advised to install the latest security update ASAP The Irish Sun reports: ANDROID users have been told to update their phones immediately to fix two bugs that allowed hackers to hijack devices. One bug, which meant hackers could install malware or steal files from devices without even needing a password, […]

Vulnerabilities, News
February 02, 2025
22 views 10 secs 0

FDA, CISA warn of backdoor in popular patient monitor used by US hospitals

The Record reports: Federal agencies are warning hospitals of a backdoor discovered in a popular line of patient monitors sold by Chinese company Contec. The Cybersecurity and Infrastructure Security Agency (CISA) and Food and Drug Administration (FDA) released warnings on Thursday about an embedded function they found in the firmware of the Contec CMS8000 — […]

Vulnerabilities, News
January 27, 2025
28 views 52 secs 0

SonicWall warns hackers targeting critical vulnerability in SMA 1000 series appliances

Researchers from Microsoft Threat Intelligence alerted the company to suspected threat activity. Cybersecurity Dive reports: SonicWall issued an alert Friday that a critical remote code execution vulnerability in its SMA appliances is under active exploitation by malicious hackers and urged customers to immediately update any vulnerable firmware. Researchers from Microsoft Threat Intelligence had warned SonicWall about the […]

Vulnerabilities
January 26, 2025
27 views 56 secs 0

ChatGPT API flaw could allow DDoS, prompt injection attacks

Another day, another vulnerability. CSO Online reports that a researcher discovered an OpenAI development oversight that could allow attackers to launch DDoS attacks on unsuspecting victims: OpenAI-owned ChatGPT might have a vulnerability that could allow threat actors to launch distributed denial of service (DDoS) attacks on unsuspecting targets.   According to a discovery made by German security researcher […]

Vulnerabilities, News
January 25, 2025
30 views 24 secs 0

Simple STARLINK Bug Let Hackers Control Every Connected Subaru

Security researchers gained complete control of Subaru vehicles worldwide using only basic customer information like license plates or ZIP codes Motor Illustrated reports: Security researchers discovered a critical vulnerability in Subaru‘s STARLINK connected vehicle service that allowed unauthorized access to vehicles and customer data across the United States, Canada, and Japan, according to a blog post published by […]

Vulnerabilities, Vendor News
January 24, 2025
25 views 4 secs 0

Patch now: Cisco fixes critical 9.9-rated, make-me-admin bug in Meeting Management

Another day, another critical patch. The Register reports: Cisco has pushed a patch for a critical, 9.9-rated vulnerability in its Meeting Management tool that could allow a remote, authenticated attacker with low privileges to escalate to administrator on affected devices. Cisco Meeting Management is the management software for the tech giant’s on-premises video meeting platform. […]

Vulnerabilities, Data Breach News
January 16, 2025
47 views 17 secs 0

Hacking group leaks Fortinet users’ details on dark web

Details from more than 15,000 devices exposed If you use Fortinet, Computing.co.uk has information that you need to know: Hackers calling themselves Belsen Group have leaked details of users of Fortinet firewalls on the dark web. Researcher Kevin Beaumont, who has reviewed the data dump, says he believes it to be genuine, since devices in […]