Security News

W3 Total Cache plugin flaw exposes 1 million WordPress sites to attacks
2025-01-16 20:36

A severe flaw in the W3 Total Cache plugin installed on more than one million WordPress sites could give attackers access to various information, including metadata on cloud-based apps. [...]

Enzo Biochem settles lawsuit over 2023 ransomware attack for $7.5M
2025-01-16 17:32

That's in addition to the $4.5M fine paid to three state AGs last year Enzo Biochem has settled a consolidated class-action lawsuit relating to its 2023 ransomware incident for $7.5 million.…

Over 660,000 Rsync servers exposed to code execution attacks
2025-01-15 17:00

Over 660,000 exposed Rsync servers are potentially vulnerable new to six new vulnerabilities, including a critical-severity heap-buffer overflow flaw that could lead to remote code execution. [...]

Patch Tuesday: January 2025 Security Update Patches Exploited Elevation of Privilege Attacks
2025-01-15 16:03

Microsoft’s monthly patches cover Hyper-V NT Kernel Integration VSPs, Git in Visual Studio, and more.

Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks
2025-01-15 05:10

Cybersecurity researchers have disclosed multiple security flaws in SimpleHelp remote access software that could lead to information disclosure, privilege escalation, and remote code execution....

Microsoft fixes under-attack privilege-escalation holes in Hyper-V
2025-01-15 01:33

Plus: Excel hell, angst for Adobe fans, and life's too Snort for Cisco Patch Tuesday The first Patch Tuesday of 2025 has seen Microsoft address three under-attack privilege-escalation flaws in its...

WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
2025-01-14 20:54

A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data. [...]

Hackers use FastHTTP in new high-speed Microsoft 365 password attacks
2025-01-14 15:57

Threat actors are utilizing the FastHTTP Go library to launch high-speed brute-force password attacks targeting Microsoft 365 accounts globally. [...]

4 Reasons Your SaaS Attack Surface Can No Longer be Ignored
2025-01-14 10:08

What do identity risks, data security risks and third-party risks all have in common? They are all made much worse by SaaS sprawl. Every new SaaS account adds a new identity to secure, a new place...

Fortinet Warns of New Zero-Day Used in Attacks on Firewalls with Exposed Interfaces
2025-01-14 09:13

Threat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management interfaces exposed on the public internet. "The campaign involved...