Aggregator
Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk
Recent analysis has revealed a concerning trend in mobile app security: Many popular apps store hardcoded and unencrypted cloud service credentials directly within their codebases. It poses a significant security risk as anyone accessing the app’s binary or source code could extract and misuse these credentials to manipulate or exfiltrate data. Examples include Pic Stitch, […]
The post Hardcoded Creds in Popular Apps Put Millions of Android and iOS Users at Risk appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-50415 | Pagup Ads.txt & App-ads.txt Manager Plugin up to 1.1.7.1 on WordPress cross site scripting
CVE-2024-50484 | Mahlamusa Multi Purpose Mail Form Plugin up to 1.0.2 on WordPress unrestricted upload
CVE-2024-47401 | Mattermost up to 9.5.9/9.10.2/9.11.1 GraphQL Response allocation of resources
CVE-2024-50493 | masterhomepage Automatic Translation Plugin up to 1.0.4 on WordPress unrestricted upload
永久激活GPT4.0!有效期至2296年!我上车了!!
PIXM protects MSPs from credential theft and phishing attacks
PIXM Security launched its new Managed Service Provider (MSP) program for zero-day phishing protection. With over 500,000 end users already protected, PIXM shields MSPs and their customers from credential theft and zero-day phishing attacks that can lead to malware and other exploits on their laptops, desktops and mobile platforms. Over 50 percent of phishing links are clicked outside corporate email. While phishing security is often associated solely with email protection, cybercriminals are adapting and increasingly … More →
The post PIXM protects MSPs from credential theft and phishing attacks appeared first on Help Net Security.
Спецслужбы раскрыли пользователей инфостилеров Redline и Meta
CVE-2024-50480 | Azexo Marketing Automation Plugin up to 1.27.80 on WordPress unrestricted upload
CVE-2024-50052 | Mattermost up to 9.5.9/9.10.2/9.11.1 Message authorization
CVE-2024-50475 | Scott Gamon Signup Page Plugin up to 1.0 on WordPress authorization
CVE-2024-50482 | Chetan Khandla Woocommerce Product Design Plugin up to 1.0.0 on WordPress unrestricted upload
CVE-2024-50494 | Amin Omer Sudan Payment Gateway for WooCommerce Plugin up to 1.2.2 on WordPress unrestricted upload
CVE-2024-50427 | Devsoft Baltic SurveyJS Plugin up to 1.9.136 on WordPress unrestricted upload
CVE-2017-2436 | Apple macOS up to 10.12.3 IOFireWireAVC memory corruption (HT207615 / EDB-40961)
CVE-2003-0507 | Microsoft Windows up to 2000 SP3 Active Directory stack-based overflow (VU#594108 / Nessus ID 26921)
ClickFix Malware Infect Website Visitors Via Hacked WordPress Websites
Researchers have identified a new variant of the ClickFix fake browser update malware distributed through malicious WordPress plugins. These plugins, disguised as legitimate tools, inject malicious JavaScript code into compromised websites, tricking users into installing malware. The malware uses blockchain technology to obtain malicious payloads, exploiting social engineering tactics to deceive victims. Over 6,000 websites […]
The post ClickFix Malware Infect Website Visitors Via Hacked WordPress Websites appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.