Aggregator
CVE-2024-44005 | Wpsoul Greenshift Plugin up to 9.3.7 on WordPress cross site scripting
CVE-2024-45453 | Maintenance Redirect Plugin up to 2.0.1 on WordPress Maintenance Mode access control
CVE-2024-44048 | wpWax Product Carousel Slider & Grid Ultimate for WooCommerce Plugin path traversal
CVE-2024-43989 | Firsh Justified Image Grid Plugin up to 4.6.1 on WordPress server-side request forgery
CVE-2024-47303 | Livemesh Addons for Elementor Plugin up to 8.5 on WordPress cross site scripting
CVE-2024-43237 | TaxoPress Tag Cloud Plugin up to 2.0.3 on WordPress information disclosure
CVE-2024-43959 | Themepoints Testimonials Plugin up to 3.0.8 on WordPress cross site scripting
CVE-2024-47305 | Dnesscarkey Use Any Font Plugin up to 6.3.08 on WordPress cross-site request forgery
CVE-2024-47315 | GiveWP Plugin up to 3.15.1 on WordPress cross-site request forgery
CVE-2024-47337 | Stuart Wilson Joy of Text Lite Plugin up to 2.3.1 on WordPress authorization
CVE-2024-47641 | WPDeveloperr Confetti Fall Animation Plugin up to 1.3.0 on WordPress cross site scripting
Минцифры назвало условия для «надежных» операторов. Цена вопроса — до 50 миллионов рублей
实验室手套可能会释放塑料颗粒影响测量结果
New 'Storm' Infostealer Remotely Decrypts Stolen Credentials
梯形比例模型
OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues
The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review before upgrading. The most notable security fix targets a shell injection vulnerability in the -J (ProxyJump) command-line option. Prior to this release, user and host names passed via -J […]
The post OpenSSH 10.3 Fixes Shell Injection and Multiple SSH Security Issues appeared first on Cyber Security News.
Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign
A seemingly routine procurement email has become the entry point for a sophisticated six-stage malware attack targeting industrial suppliers and procurement teams. The campaign, tracked as NKFZ5966PURCHASE, disguises itself as a Boeing Request for Quotation (RFQ) from a person named “Joyce Malave,” luring victims into opening a malicious Word document. Once opened, the file silently […]
The post Hackers Abuse DOCX, RTF, JS, and Python in Stealthy Boeing RFQ Malware Campaign appeared first on Cyber Security News.
OpenSSH 10.3 patches five security bugs and drops legacy rekeying support
OpenSSH 10.3 shipped carrying five security fixes alongside feature additions and a set of behavior changes that will break compatibility with older SSH implementations that do not support rekeying. Rekeying compatibility removed SSH clients and servers that lack rekeying support will fail when they attempt to interoperate with OpenSSH going forward. The project removed the bug-compatibility code that previously allowed such implementations to keep working. Deployments running non-standard or legacy SSH software should verify rekeying … More →
The post OpenSSH 10.3 patches five security bugs and drops legacy rekeying support appeared first on Help Net Security.