Announcements

Joomla 3.4.5 Released Fixing a Serious SQL Injection Vulnerability

  • 27th October 2015
The Joomla team just released a new Joomla version (3.4.5) to fix some serious security vulnerabilities. The most critical one is a remote and unauthenticated SQL injection on the com_contenthistory module (included by default) that allows for a full take over of the vulnerable site.Being proactive in the protection of your site is of ...
Continue reading

Security advisory: Stored XSS in Jetpack

  • 1st October 2015
Security Risk: DangerousExploitation Level: Easy/RemoteDREAD Score: 8/10Vulnerability: Stored XSSPatched Version:  3.7.1Vulnerability Disclosure Timeline: September 10th, 2015 – Initial report to Automattic security teamSeptember 10th, 2015 – Automattic security team acks receipt of report, sets patch date for ...
Continue reading

Cisco spots attackers hijacking its networking gear by modifying firmware

  • 14th August 2015
Cisco has issued an official warning about in-the-wild attacks that resulted in attackers gaining and potentially keeping administrative access to a Cisco IOS device indefinitely. "Cisco has observed a limited number of cases where attackers, after gaining administrative or physical access to a Cisco IOS device, replaced the Cisco IOS ROMMON (IOS ...
Continue reading

Serious Flaw in iOS Mail App Exposes Users to Phishing Attacks

  • 14th June 2015
The email client shipped with Apple’s iOS mobile operating system is plagued by a vulnerability that can be exploited to load remote arbitrary HTML content in the application, a researcher has warned. Czech researcher Jan Souček published proof-of-concept (PoC) code and a video earlier this week to demonstrate his findings. The expert ...
Continue reading