Aggregator
CVE-2024-54277 | Alireza aliniya Nias Course Plugin up to 1.2.1 on WordPress cross site scripting
词法分析 | RE 转化成 NFA Thompson 算法
CVE-2024-54273 | PickPlugins Mail Picker Plugin up to 1.0.14 on WordPress deserialization
CVE-2024-54266 | ImageRecycle PDF & Image Compression Plugin up to 3.1.16 on WordPress cross site scripting
CVE-2024-54275 | Wibergs Web CSV to HTML Plugin up to 3.04 on WordPress cross site scripting
CVE-2024-54276 | Felix Moira Poll Builder Plugin up to 1.3.5 on WordPress cross site scripting
CVE-2024-54265 | UkrSolution Barcode Scanner with Inventory & Order Manager Plugin cross site scripting
CVE-2024-54333 | silverplugins217 Check Pincode for Woocommerce Plugin up to 1.1 on WordPress cross site scripting
CVE-2024-54342 | Staggs Product Configurator for WooCommerce Plugin up to 2.0.0 on WordPress cross site scripting
CVE-2024-54264 | César Morillas Shortcodes Blocks Creator Ultimate Plugin up to 2.2.0 on WordPress cross site scripting
CVE-2024-54245 | Think201 Clients Plugin up to 1.1.4 on WordPress cross site scripting
CVE-2024-54328 | Link Nacional Invoice Payment for WooCommerce Plugin up to 1.7.2 on WordPress cross site scripting
US Indicts 14 North Koreans in IT Scam Funding WMD Programs
U.S. federal prosecutors indicted 14 North Koreans for a long-running IT scam generating $88 million by exploiting remote work with U.S. firms, a scheme prosecutors say is tied to DPRK-controlled companies that fund weapons programs through stolen identities, data theft and extortion.
Russia Used Borrowed Spyware to Target Ukrainian Troops
A Russian state-backed hacker group used third-party data-stealing bots and possibly a backdoor used by another Russia-based threat group to infiltrate and spy on devices used by frontline Ukrainian military units, according to a report from the Microsoft threat intelligence team.
Crypto Roundup: Crypto Pros Targeted With Fake Meeting Apps
This week, scammers targeted crypto workers with fake meeting apps, Australia fined Kraken crypto exchange operator Bit Trade, a Los Angeles federal court ordered five individuals to pay $5 million, Polish police detained a Russian former exchange operator and FTX debtors clawed back more cash.
Stop pushing bad WAF rules | Impart Security
Ever push a bad WAF rule? It's the worst.
For most WAF users, the number one fear isn't that the WAF is going to get bypassed. It's that a bad WAF rule will cause an outage.
Impart Security is excited to release the WAF Rule Canary Tests to solve this problem. Designed for cloud security engineers focused on balancing security with system performance, WAF Rule Canary tests let security teams make certain any new WAF rule change isn’t impacting system availability or performance by running proactive health checks against your complete WAF ruleset BEFORE pushing to production.
With WAF Rule Canary tests, Impart spins up a virtual Agent within the Impart cloud, pre-loaded with your complete WAF ruleset. Customers can then run predefined canary tests (defined as endpoints that should always be available and never be blocked, for example) against them using simulated HTTP traffic. If a canary test fails, then any new WAF rule changes will not be saved to production inspectors, proactively avoiding any potentially bad WAF rule.
In conjunction with simulated blocking mode, WAF Rule Canary tests ensure that security teams won’t create WAF rules that take down production sites.
Learn more at try.imp.art, and follow us on LinkedIn for our latest product news
The post Stop pushing bad WAF rules | Impart Security appeared first on Security Boulevard.
DEF CON 32 – Outlook Unleashing RCE Chaos CVE 2024 30103
Authors/Presenters: Michael Gorelik, Arnold Osipov
Our sincere appreciation to DEF CON, and the Presenters/Authors for publishing their erudite DEF CON 32 content. Originating from the conference’s events located at the Las Vegas Convention Center; and via the organizations YouTube channel.
The post DEF CON 32 – Outlook Unleashing RCE Chaos CVE 2024 30103 appeared first on Security Boulevard.