Aggregator
CVE-2021-4414 | Abandoned Cart Lite for WooCommerce Plugin up to 5.8.5 on WordPress wcal_preview_emails cross-site request forgery (ID 2473720)
Предупреждение АНБ — перезагрузите свой интернет-роутер прямо сейчас
What vibe hunting gets right about AI threat hunting, and where it breaks down
In this Help Net Security interview, Aqsa Taylor, Chief Security Evangelist, Exaforce, explains vibe hunting, an AI-driven approach to threat detection that inverts traditional hypothesis-driven methods. Instead of analysts defining attack vectors upfront, the AI scans datasets for anomalous patterns and surfaces potential threats. Taylor draws a firm line on responsibility: analysts must be able to explain their reasoning. When they cannot, the AI is steering the hunt. She also addresses enrichment, junior analyst development, … More →
The post What vibe hunting gets right about AI threat hunting, and where it breaks down appeared first on Help Net Security.
CVE-2021-4399 | Edwiser Bridge Plugin up to 2.0.6 on WordPress cross-site request forgery
CVE-2021-4402 | Multiple Roles Plugin up to 1.3.1 on WordPress mu_add_roles_in_signup_meta cross-site request forgery
CVE-2021-4395 | Abandoned Cart Recovery for WooCommerce Plugin up to 1.0.4 on WordPress get_items/extra_tablenav cross-site request forgery
CVE-2021-4396 | Rucy Plugin up to 0.4.4 on WordPress save_rc_post_meta cross-site request forgery
CVE-2021-4394 | Locations Plugin up to 3.2.1 on WordPress saveCustomFields cross-site request forgery
CVE-2021-4398 | Amministrazione Trasparente Plugin up to 7.1 on WordPress at_save_aturl_meta cross-site request forgery
CVE-2021-4401 | Style Kits Plugin up to 1.8.0 on WordPress update_posts_stylekit cross-site request forgery (ID 2473676)
CVE-2021-4404 | Event Espresso 4 Decaf Plugin up to 4.10.11 on WordPress ajaxHandler cross-site request forgery (ID 2554360)
CVE-2021-4403 | Remove Schema Plugin up to 1.5 on WordPress Setting validate cross-site request forgery
CVE-2021-4400 | Better Search Plugin up to 2.5.2 on WordPress Setting cross-site request forgery
CVE-2021-4405 | ElasticPress Plugin up to 3.5.3 on WordPress epio_send_autosuggest_allowed cross-site request forgery (ID 2473455)
CVE-2023-2078 | Buy Me a Coffee Plugin up to 3.7 on WordPress authorization
CVE-2023-2079 | Buy Me a Coffee Plugin up to 3.7 on WordPress cross-site request forgery (Replaces VDB-233376)
Мозг в банке — больше не фантастика. Биологи вживляют грызунам зачатки человеческих органоидов и боятся случайно породить разумных химер
CVE-2026-4482 | Rapid7 Insight Agent up to 3.3.0 on Windows Certificate …/bootstrap/common/ssl permission assignment
Health insurance lead sites sell personal data within seconds of form submission
Lead generation websites that offer health insurance quotes collect sensitive personal data and sell it to multiple buyers within seconds of a user clicking submit. A study by researchers at UC Davis, Stanford University, and Maastricht University mapped this process across 105 health insurance lead generation sites and monitored what happened to the data over 60 days. The researchers created 210 synthetic user profiles, each with a unique phone number and email address, and submitted … More →
The post Health insurance lead sites sell personal data within seconds of form submission appeared first on Help Net Security.