Announcements

Security advisory: Stored XSS in Jetpack

  • 1st October 2015
Security Risk: DangerousExploitation Level: Easy/RemoteDREAD Score: 8/10Vulnerability: Stored XSSPatched Version:  3.7.1Vulnerability Disclosure Timeline: September 10th, 2015 – Initial report to Automattic security teamSeptember 10th, 2015 – Automattic security team acks receipt of report, sets patch date for ...
Continue reading

Hijacked Wordpress websites infect visitors with malware

  • 21st September 2015
Thousands of websites that run the content management system WordPress have been hijacked by hackers to infect unsuspecting visitors with malware exploits. Although the entire campaign was initiated 15 days ago, its activity has increased tremendously in the past 2 days, as the number of websites being hijacked per day increased from 1000 to ...
Continue reading

Cisco spots attackers hijacking its networking gear by modifying firmware

  • 14th August 2015
Cisco has issued an official warning about in-the-wild attacks that resulted in attackers gaining and potentially keeping administrative access to a Cisco IOS device indefinitely. "Cisco has observed a limited number of cases where attackers, after gaining administrative or physical access to a Cisco IOS device, replaced the Cisco IOS ROMMON (IOS ...
Continue reading

WordPress 4.2.4 Security and Maintenance Release

  • 11th August 2015
WordPress 4.2.4 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. This release addresses six issues, including three cross-site scripting vulnerabilities and a potential SQL injection that could be used to compromise a site, which were discovered ...
Continue reading