PHPMailer Bug Leaves Millions of Websites Open to Attack

A critical PHPMailer bug tied to the way websites handle email and feedback forms is leaving millions of websites hosted on popular web-publishing platforms such as WordPress, Drupal and Joomla open to attack. Continue reading PHPMailer Bug Leaves Millions of Websites Open to Attack

Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine

Drupal fixed a handful of issues in version 7 and 8 of the content management system core engine that could have led to cache poisoning, social engineering attacks, and a denial of service condition. Continue reading Drupal Fixes ‘Moderately Critical’ Vulnerabilities in Core Engine

Warframe, Clash of Kings players’ info stolen after forum hacks

Two new website hack/ user data theft combos have been revealed last week, and the victims are players of popular mobile real time strategy game Clash of Kings and online free-to-play third-person shooter Warframe. In both cases the attackers found their way in by exploiting vulnerabilities in the software used by the companies to set up their online forums (vBulletin) or manage the content on their site (Drupal). The Clash of Kings hack The Clash … More Continue reading Warframe, Clash of Kings players’ info stolen after forum hacks

Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net

Are you a fan of Warframe?
Is so, Digital Extremes, the company behind the popular online game has some bad news for you.
Read more in my article on the Tripwire State of Security blog.
Continue reading Drupalgeddon hits Warframe – nearly 800,000 gamers’ account details being sold on the net

3 Popular Drupal Modules Found Vulnerable — Patch Released

Just yesterday, I wrote a warning article announcing that Drupal – the popular open source content management system – will release patches for several highly critical Remote Code Execution (RCE) bugs that could allow attackers to fully take over any affected site.

Below are the three separate Drupal modules that affect up to 10,000 websites:

1. RESTful Web Services – a popular module used

Continue reading 3 Popular Drupal Modules Found Vulnerable — Patch Released

Drupal Patches Remote Code Execution Vulnerabilities in Three Modules

Developers with the open source content management framework Drupal patched a series of highly critical remote code execution bugs in three separate modules today. If exploited, the bugs could let an attacker take over any site running the modules.

Continue reading Drupal Patches Remote Code Execution Vulnerabilities in Three Modules