Aggregator
CVE-2015-9299 | events-manager Plugin up to 5.5.7.0 on WordPress DOM-Based cross site scripting
CVE-2015-9300 | events-manager Plugin up to 5.5.6 on WordPress cross site scripting
CVE-2012-6716 | events-manager Plugin up to 5.1.6 on WordPress JSON Call Links cross site scripting
CVE-2013-7477 | events-manager Plugin up to 5.5.1 on WordPress Booking Form cross site scripting
CVE-2013-7478 | events-manager Plugin up to 5.4 on WordPress EM_Ticket::get_post cross site scripting
CVE-2013-7479 | events-manager Plugin up to 5.3.8 on WordPress Search Form cross site scripting
CVE-2013-7480 | events-manager Plugin up to 5.3.6.0 on WordPress Admin Area cross site scripting
CVE-2019-16523 | events-manager Plugin up to 5.9.5 on WordPress Shortcode Stored cross site scripting
Patch Tuesday Update – October 2024
The post Patch Tuesday Update - October 2024 appeared first on Digital Defense.
The post Patch Tuesday Update – October 2024 appeared first on Security Boulevard.
A decade of transformation: ADDO and the State of the Software Supply Chain
The software industry has seen remarkable changes over the past decade, driven by a surge in open source adoption, evolving development methodologies, and the growing integration of AI.
At this year's All Day DevOps (ADDO) event, a panel of industry leaders, including Sonatype's co-founder and CTO Brian Fox, will present "A Decade of Transformation - Unveiling the 10th Annual State of the Software Supply Chain Report."
This session promises to reveal key insights into how the software supply chain has evolved and what the future holds.
The post A decade of transformation: ADDO and the State of the Software Supply Chain appeared first on Security Boulevard.
Microsoft security advisory – October 2024 monthly rollup (AV24–574)
New Mamba 2FA bypass service targets Microsoft 365 accounts
Adobe security advisory (AV24–573)
CVE-2014-7498 | Xaos Space Cinema 2.0.6 X.509 Certificate cryptographic issues (VU#582497)
GoldenJackal Targets Embassies, Steals Data from Air-Gapped Systems
GoldenJackal, a threat group possibly from Russia, has been attacking embassies and other government agencies from Europe, South Asia, and the Middle East with two distinct malicious toolsets designed to steal information from air-gapped systems, ESET researchers said.
The post GoldenJackal Targets Embassies, Steals Data from Air-Gapped Systems appeared first on Security Boulevard.
CVE-2012-5917 | Tom Wilkason SnackAmp 3.1.3 memory corruption (EDB-18692 / XFDB-74528)
Revolutionizing software development: Frank Roe’s keynote at ADDO
The world of software development is rapidly evolving, driven by increasing pressure to deliver faster, yet with fewer resources, and the widespread adoption of generative AI tools.
The post Revolutionizing software development: Frank Roe’s keynote at ADDO appeared first on Security Boulevard.