Update now! Popular WordPress plugins have password bypass flaws

Credit to Author: John E Dunn| Date: Thu, 16 Jan 2020 13:47:38 +0000

Researchers have discovered bad authentication bypass vulnerabilities affecting two WordPress plugins which should be patched as soon as possible.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/qhJn8G3sG5M” height=”1″ width=”1″ alt=””/>

Read more

Microsoft fixes critical bugs in CryptoAPI, RD Gateway and .NET

Credit to Author: Danny Bradbury| Date: Wed, 15 Jan 2020 12:10:33 +0000

Here are the most serious bugs from Microsoft’s Patch Tuesday – Including CryptoAPI and RCE flaws in Windows Remote Desktop Gateway.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/_JcrLmlUQmc” height=”1″ width=”1″ alt=””/>

Read more

Malicious npm package taken down after Microsoft warning

Credit to Author: John E Dunn| Date: Wed, 15 Jan 2020 11:32:56 +0000

Criminals have been caught trying to sneak a malicious package on to the popular Node.js platform npm (Node Package Manager).<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/X4lFsmpAVr8″ height=”1″ width=”1″ alt=””/>

Read more

‘Cable Haunt’ vulnerability exposes 200 million cable modem users

Credit to Author: John E Dunn| Date: Tue, 14 Jan 2020 11:41:45 +0000

A fortnight in to 2020 and we have the first security flaw to be given its own name: Cable Haunt – complete with eye-catching logo.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/xgn6q9BSap4″ height=”1″ width=”1″ alt=””/>

Read more

Lottery hacker gets 9 months for his £5 cut of the loot

Credit to Author: Lisa Vaas| Date: Tue, 14 Jan 2020 11:18:57 +0000

We don’t care how little you made from your crimes, the judge said. We care that you went after an outfit that gives a ton to charities.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/MQxKTz5FL8E” height=”1″ width=”1″ alt=””/>

Read more

Powerful GPG collision attack spells the end for SHA-1

Credit to Author: Danny Bradbury| Date: Mon, 13 Jan 2020 13:54:29 +0000

New research has heightened an already urgent call to abandon SHA-1, a cryptographic algorithm still used in many popular online services.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/4sQ-pLfUpIU” height=”1″ width=”1″ alt=””/>

Read more

Ransomware pounces on California schools, Las Vegas trounces attack

Credit to Author: Lisa Vaas| Date: Fri, 10 Jan 2020 10:43:29 +0000

We’ll have one serving of whatever Las Vegas is eating and wish Pittsburg Unified School District good luck with getting unstuck.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/ZYdKmx-4lMo” height=”1″ width=”1″ alt=””/>

Read more

Google’s Project Zero highlights patch quality with policy tweak

Credit to Author: Danny Bradbury| Date: Thu, 09 Jan 2020 11:26:07 +0000

Google’s Project Zero bug-hunting team has tweaked its 90-day responsible disclosure policy to help improve the quality and adoption of vendor patches.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/45XsE2-NHPY” height=”1″ width=”1″ alt=””/>

Read more

REvil ransomware exploiting VPN flaws made public last April

Credit to Author: John E Dunn| Date: Wed, 08 Jan 2020 12:39:53 +0000

Researchers report flaws, vendors issue patches, organisations apply them – and everyone lives happily ever after. Right? Wrong!<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/FOp5i99FBQk” height=”1″ width=”1″ alt=””/>

Read more