WooCommerce Pricing Plugin Allows Malicious Code-Injection
The popular Dynamic Pricing and Discounts plugin from Envato can be exploited by unauthenticated attackers. Continue reading WooCommerce Pricing Plugin Allows Malicious Code-Injection
Collaborate Disseminate
The popular Dynamic Pricing and Discounts plugin from Envato can be exploited by unauthenticated attackers. Continue reading WooCommerce Pricing Plugin Allows Malicious Code-Injection
The bug (CVE-2021-33766) is an information-disclosure issue that could reveal victims’ personal information, sensitive company data and more. Continue reading Microsoft Exchange ‘ProxyToken’ Bug Allows Email Snooping
It’s unclear if Microsoft customers were breached during the months-long period where the #ChaosDB bug in Jupyter Notebooks was exploitable. Continue reading Critical Azure Cosmos DB Bug Allows Full Cloud Account Takeover
The issue affects a range of Cisco Wireless-N and Wireless-AC VPN routers that have reached end-of-life. Continue reading Critical Cisco Bug in Small Business Routers to Remain Unpatched
The apps attempt to swindle users into buying in-app upgrades or clicking on masses of ads. Continue reading Bogus Cryptomining Apps Infest Google Play
The OS command-injection bug, in the web application firewall (WAF) platform known as FortiWeb, will get a patch at the end of the month. Continue reading Unpatched Fortinet Bug Allows Firewall Takeovers
Fresh attacks target companies’ employees, promising millions of dollars in exchange for valid account credentials for initial access. Continue reading LockBit 2.0 Ransomware Proliferates Globally
The bug would allow a number of malicious actions, up to and including full site takeover. The vulnerable plugin is installed on 100,000 websites. Continue reading XSS Bug in SEOPress WordPress Plugin Allows Site Takeover
CAPTCHA-protected malicious URLs are snowballing lately, researchers said. Continue reading Cyberattackers Embrace CAPTCHAs to Hide Phishing, Malware
A crush of new attacks using the well-known adware involves at least 150 updated samples, many of which aren’t recognized by Apple’s built-in security controls. Continue reading AdLoad Malware 2021 Samples Skate Past Apple XProtect