Announcements

SQL Injection, Other Vulnerabilities Found in InfiniteWP Admin Panel

  • 15th December 2014
Researchers have uncovered several vulnerabilities in the admin panel of InfiniteWP, a free application that allows WordPress website administrators to control multiple installations from a single dashboard. The client for the WordPress management platform has been downloaded more than 875,000 times from the official WordPress website, and ...
Continue reading

'Critical' security bugs dating back to 1987 found in X Window

  • 15th December 2014
27-year-old flaw and others slain in open-source patch batch X.org, which develops the open-source X Window System for Linux and other Unix-y desktops, has warned security flaws have been discovered in the code – and some of them have been hanging around for 27 years. The bugs can be exploited by applications to crash the window system, or ...
Continue reading

RIG Exploit Kit Used in Drupal CMS Exploit Incidents

  • 5th November 2014
The public disclosure of a critical SQL injection vulnerability affecting all builds of Drupal 7, save for the last one, gave way to increased cybercriminal activity leveraging the RIG Exploit Kit to compromise website visitors through drive-by download attacks. The bad actors would rely on a simple redirect method via an iframe injected into the ...
Continue reading

Attackers Abuse UPnP Devices in DDoS Attacks, Akamai Warns

  • 18th October 2014
Researchers at Akamai Technologies have issued a warning about a spate of distributed denial-of-service attacks being launched via Universal Plug and Play (UPnP) devices.   According to Akamai's Prolexic Security Engineering & Response Team (PLXsert), there has been a spike in reflection and amplification distributed ...
Continue reading