Bugs, Breaches, and More! – Application Security Weekly #55

XSS Vulnerability in Abandoned Cart Plugin Leads to WordPress Site Takeover, The RedMonk Programming Language Rankings: January 2019, I Deleted Facebook Last Year; Here’s What Changed (and What Didn’t), CommitStrip: Over-excited, and more! … Continue reading Bugs, Breaches, and More! – Application Security Weekly #55

Severe Flaw Disclosed In StackStorm DevOps Automation Software

A security researcher has discovered a severe vulnerability in the popular, open source event-driven platform StackStorm that could allow remote attackers to trick developers into unknowingly execute arbitrary commands on targeted services.

StackStorm… Continue reading Severe Flaw Disclosed In StackStorm DevOps Automation Software

Another Critical Flaw Found In Drupal Core—Patch Your Sites Immediately

It’s time to update your Drupal websites, once again.

For the second time within a month, Drupal has been found vulnerable to another critical vulnerability that could allow remote attackers to pull off advanced attacks including cookie theft, keylogg… Continue reading Another Critical Flaw Found In Drupal Core—Patch Your Sites Immediately

Microsoft Issues Patches For Severe Flaws, Including Office Zero-Day & DNS Attack

As part of its “October Patch Tuesday,” Microsoft has today released a large batch of security updates to patch a total of 62 vulnerabilities in its products, including a severe MS office zero-day flaw that has been exploited in the wild.

Security upd… Continue reading Microsoft Issues Patches For Severe Flaws, Including Office Zero-Day & DNS Attack

Yahoo Flaw Allowed Hackers to Read Anyone’s Emails

Yahoo has patched a critical security vulnerability in its Mail service that could have allowed an attacker to spy on any Yahoo user’s inbox.

Jouko Pynnönen, a Finnish Security researcher from security firm Klikki Oy, reported a DOM based persistent XSS (Cross-Site Scripting) in Yahoo mail, which if exploited, allows an attacker to send emails embedded with malicious code.
<!– adsense –>
In

Continue reading Yahoo Flaw Allowed Hackers to Read Anyone’s Emails

Yahoo Flaw Allowed Hackers to Read Anyone’s Emails

Yahoo has patched a critical security vulnerability in its Mail service that could have allowed an attacker to spy on any Yahoo user’s inbox.

Jouko Pynnönen, a Finnish Security researcher from security firm Klikki Oy, reported a DOM based persistent XSS (Cross-Site Scripting) in Yahoo mail, which if exploited, allows an attacker to send emails embedded with malicious code.
<!– adsense –>
In

Continue reading Yahoo Flaw Allowed Hackers to Read Anyone’s Emails