Aggregator
CVE-2024-47335 | Bit Form Plugin up to 2.13.11 on WordPress sql injection
CVE-2024-47344 | StylemixThemes uListing Plugin up to 2.1.5 on WordPress information disclosure
CVE-2024-47334 | Zoho Flow Plugin up to 2.7.1 on WordPress sql injection
CVE-2024-47354 | smp7 Simple Membership After Login Redirection Plugin up to 1.6 on WordPress redirect
CVE-2024-47636 | Eyecix JobSearch Plugin up to 2.5.9 on WordPress deserialization
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 91
Обновили axios? Поздравляем, теперь вы заражены. Хакеры превратили библиотеку в троян и раздали его миллионам разработчиков
New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In
What happened New Progress ShareFile bugs could let attackers take over exposed on-premises servers without logging in by chaining an authentication bypass with remote code execution. The issues affect customer-managed ShareFile Storage Zones Controller 5.x deployments. The first flaw, CVE-2026-2699, is an authentication bypass on the Admin.aspx configuration page that can expose restricted admin functionality […]
The post New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In appeared first on CISO Whisperer.
The post New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In appeared first on Security Boulevard.
Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak
What happened Hackers are weaponizing the leaked Claude Code source to spread Vidar and GhostSocks malware through malicious repositories that impersonate the exposed codebase. The campaign followed Anthropic’s March 31 packaging error, which exposed the source code for Claude Code in a public npm package through a JavaScript source map file containing more than half […]
The post Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak appeared first on CISO Whisperer.
The post Hackers Spread Vidar and GhostSocks Malware Through Claude Code Leak appeared first on Security Boulevard.