Security News

Vulnerability Allowing Full Server Takeover Found in Concrete5 CMS
2020-08-18 15:35

A remote code execution vulnerability addressed recently in Concrete5 exposed numerous websites to attacks, Edgescan reports. What Edgescan discovered was an RCE flaw in Concrete5 that could have allowed an attacker to inject a reverse shell into vulnerable web servers, thus taking full control of them.

Over 30 Vulnerabilities Discovered Across 20 CMS Products
2020-08-10 10:31

Researchers have identified more than 30 vulnerabilities across 20 popular content management systems, including Microsoft SharePoint and Atlassian Confluence. "In the most simple attack scenario, the attacker has access to the target CMS applications such as regular Sharepoint users being able to create their own sites and therefore being able to provide their own templates," Muñoz explained.

Anti-NATO Disinformation Campaign Leveraged CMS Compromises
2020-07-31 16:03

The influence campaign does not merely spread false news content on social media platforms such as Twitter and Facebook, as other disinformation campaigns have done. "We have dubbed this campaign 'Ghostwriter,' based on its use of inauthentic personas posing as locals, journalists, and analysts within the target countries to post articles and op-eds referencing the fabrications as source material to a core set of third-party websites that publish user-generated content," according to FireEye researchers in a Thursday analysis.

Drupal Warns Web Admins to Update CMS Sites to Patch a Critical Flaw
2019-12-19 06:42

If you haven't recently updated your Drupal-based blog or business website to the latest available versions, it's the time. Drupal development team yesterday released important security updates...

Pass the salt! Popular CMSs aren’t securing passwords properly
2019-06-19 12:23

A group of researchers has discovered that many of the web's most popular content management systems are using obsolete algorithms to protect their users' passwords.

Drupal Releases Core CMS Updates to Patch Several Vulnerabilities
2019-04-17 22:03

Drupal, the popular open-source content management system, has released security updates to address multiple "moderately critical" vulnerabilities in Drupal Core that could allow remote attackers...

Hackers Target Fresh Drupal CMS Flaw to Infiltrate Sites
2019-02-22 13:33

CMS Project Team Patches "Highly Critical" Remote Code Execution VulnerabilityPatch alert: Some versions of the popular content management system Drupal have a "highly critical" flaw that...

Versasec unveils vSEC:CMS S-Series v5.4
2019-02-11 01:45

Versasec, the leader in smart card management systems, rolled out the latest generation of its flagship identity and access management (IAM) solution. vSEC:CMS S-Series v5.4 incorporates a variety...

CMS: Placing Orders Via Text Not Allowed
2018-01-08 17:18

Security Experts Weigh In on Appropriate Uses of Secure TextingFederal regulators have clarified that the use of texting to place orders, such as for medications or tests, on any platform - secure...

CMS Airship: Free secure content management (Help Net Security)
2016-07-14 13:15

CMS Airship is a free content management system designed and maintained by a team of PHP security experts at Paragon Initiative Enterprises. The web interface for managing your HTTP Public Key...