Vulnerabilita’
I più recenti attacchi Ransomware nel 2021
Siamo solo a metà del 2021, e il mondo ha subito attacchi ransomware da record su infrastrutture critiche, scuole e reti sanitarie. Anche le organizzazioni che offrono prodotti per aiutare il recupero da attacchi ransomware, come le compagnie di assicurazione informatica e i fornitori di backup dei dati, non sono rimaste al sicuro. Massicce richieste di riscatto sono state segnalate…
Attacco Magecart: cos’è e come proteggersi
Ogni giorno sentiamo parlare di qualche nuova minaccia o vulnerabilità in ambito tecnologico. Ultimamente si parla dell’attacco di raccolta dati conosciuto come “Magecart”. Cerchiamo di capire di cosa si tratta e come possiamo fare per difenderci. Magecart è un grande gruppo di hacker così come un tipico attacco che prende di mira principalmente icarrelli della spesa dei negozi online. Questo…
WastedLocker: Ransomware di ultima generazione
Tempo di lettura: 6 min WastedLocker e’ un software per attacchi ransomware che ha iniziato a colpire imprese e altre organizzazioni nel maggio 2020. E’ noto per le sue elevate richieste di riscatto che raggiungono milioni di dollari per vittima. E’ il prodotto di un gruppo di criminali informatici altamente qualificati che operano da oltre un decennio: Evil Corp. Chi…
Path traversal in Photo Gallery (WordPress plugin)
Path traversal in Photo Gallery may allow admins to read most files on the filesystem (WordPress plugin)
CVE-2017-7620 Mantis Bug Tracker
CVE-2017-7620 Mantis Bug Tracker 1.3.10 / v2.3.0 CSRF Permalink Injection
[CVE-2017-5868] OpenVPN Access Server
[CVE-2017-5868] OpenVPN Access Server : CRLF injection with Session fixation
Linux Kernel Privilege Escalation
SSD Advisory – Linux Kernel XFRM Privilege Escalation
SSD Advisory – Linux Kernel AF_PACKET Use-After-Free
SSD Advisory – Webmin Multiple Vulnerabilities
SSD Advisory – PHP Melody Multiple Vulnerabilities
DefenseCode ThunderScan SAST Advisory: WordPress Ad Widget Plugin Local File Inclusion Security Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Simple Login Log Plugin Multiple SQL Injection Security Vulnerabilities
WordPress does not hash or expire wp_signups.activation_key allowing an attacker with SQL injection to create accounts
DefenseCode Security Advisory: Magento Commerce CSRF, Stored Cross Site Scripting #1
Exploit toolkit for CVE-2017-8759 – Microsoft .NET Framework RCE (Builder + listener + video tutorial)
DefenseCode ThunderScan SAST Advisory: WordPress PressForward Plugin Security Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Podlove Podcast Publisher Plugin Security Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Easy Modal Plugin Multiple Security Vulnerabilities
Stop User Enumeration allows user enumeration via the REST API (WordPress plugin)
Defense in depth — the Microsoft way (part 48): privilege escalation for dummies — they didn’t make SUCH a stupid blunder?
Multiple Local Privilege Escalation Vulnerabilities in Acunetix Web Vulnerability Scanner 11
DefenseCode ThunderScan SAST Advisory: WordPress AffiliateWP Plugin Security Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Huge-IT Video Gallery Plugin Security Vulnerability
Joomla com_tag v1.7.6 – (tag) SQL Injection Vulnerability
Qualys Security Advisory – CVE-2017-1000367 in Sudo’s get_process_ttyname() for Linux
Defense in depth — the Microsoft way (part 48): privilege escalation for dummies — they didn’t make SUCH a stupid blunder?
Microsoft Dynamic CRM 2016 – Cross-Site Scripting vulnerability
Executable installers are vulnerable^WEVIL (case 52): escalation of privilege with Microsoft’s .NET Framework installers
Reflected XSS in WordPress Download Manager could allow an attacker to do almost anything an admin can (WordPress plugin)
DefenseCode ThunderScan SAST Advisory: WordPress All In One Schema.org Rich Snippets Plugin Security Vulnerability
[CVE-2017-5868] OpenVPN Access Server : CRLF injection with Session fixation
Stealing Windows Credentials Using Google Chrome
WordPress EELV Newsletter v4.5 – Multiple Vulnerabilities
DefenseCode ThunderScan SAST Advisory: GOOGLE google-api-php-client Multiple Security Vulnerabilities
DefenseCode WebScanner DAST Advisory: WordPress User Access Manager Plugin Security Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Tracking Code Manager Plugin Multiple Security Vulnerabilities
CSRF in wordpress plugin clean login allows remote attacker change wordpress login redirect url or logout redirect url to evil address
DefenseCode ThunderScan SAST Advisory: WordPress WebDorado Gallery Plugin SQL Injection Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Spider Event Calendar Plugin SQL Injection Vulnerability
DefenseCode ThunderScan SAST Advisory: WordPress Facebook Plugin SQL Injection Vulnerability
Cross-Site Scripting vulnerability in Trust Form WordPress Plugin
Popup by Supsystic WordPress plugin vulnerable to Cross-Site Request Forgery
Stored Cross-Site Scripting vulnerability in User Login Log WordPress Plugin
Cross-Site Request Forgery & Cross-Site Scripting in Contact Form Manager WordPress Plugin
Stored Cross-Site Scripting vulnerability in Contact Form WordPress Plugin
Remote file upload vulnerability in WordPress Plugin Mobile App Native 3.0
Cross-Site Request Forgery in WordPress Press This function allows DoS
Persistent Cross-Site Scripting in the WordPress NewStatPress plugin
Cross-Site Request Forgery in Atahualpa WordPress Theme
Cross-Site Scripting in Magic Fields 1 WordPress Plugin
Cross-Site Scripting in Google Analytics Dashboard WordPress Plugin
WordPress Adminer plugin allows public (local) database login
Cross-Site Request Forgery in WordPress Download Manager Plugin
Simple Ads Manager WordPress plugin unauthenticated PHP Object injection vulnerability
Cross-Site Request Forgery in Global Content Blocks WordPress Plugin
Cross-Site Request Forgery in File Manager WordPress plugin
Cross-Site Scripting vulnerability in WP-Filebase Download Manager WordPress Plugin
Admin Custom Login WordPress plugin custom login page affected by persistent Cross-Site Scripting
Admin Custom Login WordPress plugin affected by persistent Cross-Site Scripting via Logo URL field
Analytics Stats Counter Statistics WordPress Plugin unauthenticated PHP Object injection vulnerability
WordPress Plugin Kama Click Counter 3.4.9 – Blind SQL Injection
WordPress Plugin Easy Table 1.6 – Persistent Cross-Site Scripting
Persistent Cross-Site Scripting vulnerability in User Access Manager WordPress Plugin
Cross-Site Request Forgery vulnerability in FormBuilder WordPress Plugin allows plugin permissions modification
CMS Commander Client WordPress Plugin unauthenticated PHP Object injection vulnerability
New exploit for new vulnerability in WordPress Plugin + tutorial
Nginx (Debian-based + Gentoo distros) – Root Privilege Escalation [CVE-2016-1247 UPDATE]
Multiple vulnerabilities in cPanel <= 60.0.34
MySQL / MariaDB / PerconaDB – Privilege Escalation / Race Condition Exploit [CVE-2016-6663 / OCVE-2016-5616]
Cross-Site Scripting in Check Email WordPress Plugin
Cross-Site Scripting in All In One WP Security & Firewall WordPress Plugin
Nginx (Debian-based distros) – Root Privilege Escalation Vulnerability (CVE-2016-1247)
Stored Cross-Site Scripting vulnerability in 404 to 301 WordPress Plugin
Cross-Site Scripting in Calendar WordPress Plugin
Cross-Site Scripting vulnerability in Caldera Forms WordPress Plugin
Cross-Site Scripting vulnerability in Quotes Collection WordPress Plugin
MySQL / MariaDB / PerconaDB – Root Privilege Escalation Exploit ( CVE-2016-6664 / CVE-2016-5617 )
[oss-security] CVE request:Lynx invalid URL parsing with ‘?’
Customers
Twitter FEED
Recent activity
-
SecureOnlineDesktop
Estimated reading time: 6 minutes L'impatto crescente delle minacce informatiche, su sistemi operativi privati op… https://t.co/FimxTS4o9G
-
SecureOnlineDesktop
Estimated reading time: 6 minutes The growing impact of cyber threats, on private or corporate operating systems… https://t.co/y6G6RYA9n1
-
SecureOnlineDesktop
Tempo di lettura stimato: 6 minuti Today we are talking about the CTI update of our services. Data security is… https://t.co/YAZkn7iFqa
-
SecureOnlineDesktop
Estimated reading time: 6 minutes Il tema della sicurezza delle informazioni è di grande attualità in questo peri… https://t.co/tfve5Kzr09
-
SecureOnlineDesktop
Estimated reading time: 6 minutes The issue of information security is very topical in this historical period ch… https://t.co/TP8gvdRcrF
Newsletter
{subscription_form_2}© 2024 Cyberfero s.r.l. All Rights Reserved. Sede Legale: via Statuto 3 - 42121 Reggio Emilia (RE) – PEC [email protected] Cod. fiscale e P.IVA 03058120357 – R.E.A. 356650 Informativa Privacy - Certificazioni ISO