WordPress last week released patches for 11 vulnerabilities, including a flaw that could potentially lead to remote code execution (RCE). Dubbed Click2Shell, the flaw does not have a CVE identifier yet. In its advisory, WordPress explains that it could be… Read More "WordPress Patches ‘Click2Shell’ Vulnerability – SecurityWeek"
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites. Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of… Read More "Brevo Supply Chain Attack Injects Malware Into 100,000 Websites"
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
More than 200,000 WordPress websites are potentially exposed to takeover attacks via two critical-severity vulnerabilities in The Events Calendar plugin. A highly popular plugin with over 600,000 active installations, The Events Calendar allows administrators to easily create and manage an… Read More "Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover"