Security researchers report a massive uptick in the number of MongoDB databases hijacked and held for ransom.
Tag Archives: Vulnerabilities
PHPMailer, SwiftMailer Updates Resolve Critical Remote Code Execution Vulnerabilities
Critical remote code execution vulnerabilities in PHPMailer and SwiftMailer, libraries used to send emails via PHP, were patched this week.
PHPMailer Bug Leaves Millions of Websites Open to Attack
A critical PHPMailer bug tied to the way websites handle email and feedback forms is leaving millions of websites hosted on popular web-publishing platforms such as WordPress, Drupal and Joomla open to attack.
Clever Facebook Hack Reveals Private Email Address of Any User
A bug bounty hunter earned $5,000 for a Facebook hack that allowed him to bypass security protection and access any Facebook user’s true email address.
Siemens Patches Insufficient Entropy Vulnerability in ICS Systems
German industrial giant Siemens has provided a firmware update addressing software vulnerabilities that are found in a popular line of its Desigo PX industrial control hardware.
Nagios Core Patches Root, RCE Vulnerabilities
Nagios Core has been updated to take care of two critical vulnerabilities that can be pinned together to attack servers hosting the open source IT infrastructure monitoring software.
Tales of WordPress Plugin Insecurity Overblown, Researchers Say
The insecurity of WordPress plugins has been well documented, especially over the last year, but in the grand scheme of things, it’s not as bad as it seems, experts claim.
Threatpost News Wrap, December 16, 2016
Mike Mimoso and Chris Brook discuss the news of the week including Yahoo’s latest breach announcement, a DDoS-for-hire crackdown, hackers seeking help with Mirai, and some new Adobe patches.
DNSChanger Exploit Kit Hijacks Routers, Not Browsers
An exploit kit called DNSChanger is attacking routers, not browsers, through a malvertising campaign.
Microsoft, Google to Block Flash by Default in Edge, Chrome
Microsoft followed Google’s lead and said it will soon block Flash Player by default in the Edge browser.