Aggregator
CVE-2024-49257 | Denis Azz Anonim Posting Plugin up to 0.9 on WordPress unrestricted upload
Submit #785315: Belkin F9K1122 1.00.33 Stack-based Buffer Overflow [Accepted]
[un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness
Author, Creator & Presenter: Joshua Saxe, Al Security Technical Lead, Meta
Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations') YouTube Channel.
The post [un]prompted 2026 – The Hard Part Isn’t Building The Agent: Measuring Effectiveness appeared first on Security Boulevard.
[un]prompted 2026 – Guardrails Beyond Vibes
Author, Creator & Presenter: Jeffrey Zhang, Security Engineer, Stripe & Siddh Shah, Software Engineer, Stripe
Our thanks to [un]prompted for publishing their Creators, Authors and Presenter’s outstanding [un]prompted 2026 AI Security Practitioner content on the Organizations') YouTube Channel.
The post [un]prompted 2026 – Guardrails Beyond Vibes appeared first on Security Boulevard.
CVE-2024-47350 | YITH WooCommerce Ajax Search Plugin up to 2.8.0 on WordPress sql injection
CVE-2024-47338 | WPExpertsio WPExperts Square For GiveWP Plugin up to 1.3 on WordPress sql injection
CVE-2024-47650 | Axton WP-WebAuthn Plugin up to 1.3.1 on WordPress cross site scripting
CVE-2024-44037 | MagePeople Team Multipurpose Ticket Booking Manager Plugin up to 4.2.2 on WordPress cross site scripting
CVE-2024-44039 | WP Travel Plugin up to 9.3.1 on WordPress cross site scripting
CVE-2024-44040 | Plainware ShiftController Employee Shift Scheduling Plugin up to 4.9.64 on WordPress cross site scripting
CVE-2024-47335 | Bit Form Plugin up to 2.13.11 on WordPress sql injection
CVE-2024-47344 | StylemixThemes uListing Plugin up to 2.1.5 on WordPress information disclosure
CVE-2024-47334 | Zoho Flow Plugin up to 2.7.1 on WordPress sql injection
CVE-2024-47354 | smp7 Simple Membership After Login Redirection Plugin up to 1.6 on WordPress redirect
CVE-2024-47636 | Eyecix JobSearch Plugin up to 2.5.9 on WordPress deserialization
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91
Обновили axios? Поздравляем, теперь вы заражены. Хакеры превратили библиотеку в троян и раздали его миллионам разработчиков
New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In
What happened New Progress ShareFile bugs could let attackers take over exposed on-premises servers without logging in by chaining an authentication bypass with remote code execution. The issues affect customer-managed ShareFile Storage Zones Controller 5.x deployments. The first flaw, CVE-2026-2699, is an authentication bypass on the Admin.aspx configuration page that can expose restricted admin functionality […]
The post New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In appeared first on CISO Whisperer.
The post New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In appeared first on Security Boulevard.
Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak
What happened Hackers are weaponizing the leaked Claude Code source to spread Vidar and GhostSocks malware through malicious repositories that impersonate the exposed codebase. The campaign followed Anthropic’s March 31 packaging error, which exposed the source code for Claude Code in a public npm package through a JavaScript source map file containing more than half […]
The post Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak appeared first on CISO Whisperer.
The post Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak appeared first on Security Boulevard.