Aggregator
CVE-2022-40217 | XplodedThemes WPide Plugin up to 2.6 on WordPress unrestricted upload
CVE-2022-38061 | Apasionados Export Post Info Plugin up to 1.2.0 on WordPress csv injection
CVE-2022-40310 | WP Rating System Plugin up to 3.3.4 on WordPress Vote race condition
CVE-2021-36865 | ExpressTech Quiz and Survey Master Plugin up to 7.3.4 on WordPress resource injection
CVE-2021-36906 | ExpressTech Quiz and Survey Master Plugin up to 7.3.6 on WordPress resource injection
CVE-2022-40205 | wpForo Forum Plugin up to 2.0.5 on WordPress resource injection
CVE-2022-40206 | wpForo Forum Plugin up to 2.0.5 on WordPress resource injection
CVE-2022-45077 | Betheme Theme up to 26.5.1.4 on WordPress code injection
CVE-2022-40200 | wpForo Forum Plugin up to 2.0.9 on WordPress unrestricted upload
CVE-2022-41791 | ProfileGrid Plugin up to 5.1.6 on WordPress csv injection
New infosec products of the week: February 21, 2025
Here’s a look at the most interesting products from the past week, featuring releases from 1Password, Fortinet, Pangea, Privacera, and Veeam Software. Fortinet enhances FortiAnalyzer to deliver accelerated threat hunting and incident response FortiAnalyzer offers a streamlined entry point to scale an organization’s security operations center (SOC), providing broad coverage for both on-premises and cloud environments from a single platform. With ready-to-deploy capabilities that deliver complete control with centralized visibility, advanced threat detection, and automated … More →
The post New infosec products of the week: February 21, 2025 appeared first on Help Net Security.
Assessing and Mitigating Telehealth Privacy, Security Risks
Australia's Anti-Scams Bill: What's in It for Victims?
Australia's new scams framework bill sets the foundation for industry action but leaves consumers with limited protection. Experts warn that enforcement and reimbursement mechanisms are unclear, forcing victims to navigate a complex system with little guarantee of compensation.
Breach Roundup: FBI Publishes Ghost Warning
This week, a FBI warning on Ghost ransomware, Lee Enterprises confirmed its ransomware attack, a proof of concept for Ivanti EPM flaws and a cybersecurity flaw in a Xerox machine. Also, a Chinese cyberespionage hacker apparently moonlighted as a ransomware attacker and NioCorp hit by a cyber heist.
New AppViewX CEO Eyes Expansion in Identity, Post-Quantum
Dino DiMarino, the new CEO of AppViewX, is steering the company toward growth by expanding its presence in cybersecurity and cloud infrastructure. His strategic focus includes scaling operations, strengthening non-human identity security and safeguarding post-quantum cryptography advancements.
Feds Fine Eyeglass Retailer $1.5M for HIPAA Lapses in Hacks
Federal regulators have levied a $1.5 million HIPAA civil monetary penalty against eyeglass maker and retailer Warby Parker over credential stuffing hacks that affected about 200,000 people. The HIPAA enforcement action is the first disclosed in the second Trump administration.
Спецслужбы КНР три года прослушивали секретные каналы связи США
Google Released PoC Exploit For Palo Alto Firewall Command Injection Vulnerability
Google’s Project Zero and Mandiant cybersecurity teams have jointly published a proof-of-concept (PoC) exploit for a high-severity command injection vulnerability in Palo Alto Networks’ PAN-OS OpenConfig plugin. Tracked as CVE-2025-0110, the flaw allows authenticated administrators to execute arbitrary commands on firewalls via manipulated gNMI requests, escalating privileges to root access. The disclosure follows Palo Alto […]
The post Google Released PoC Exploit For Palo Alto Firewall Command Injection Vulnerability appeared first on Cyber Security News.