Security News

Week in review: Keeping up with ransomware, critical PHP RCE exploited, DevOps firewall
2019-11-03 15:00

Here’s an overview of some of last week’s most interesting news and articles: Leading domain name registrars suffered data breach Web technology company Web.com and its subsidiaries – domain name...

PHP team fixes nasty site-owning remote execution bug
2019-10-29 11:48

The PHP development team has fixed a bug that could allow remote code execution in some setups of the programming language.

PHP Bug Allows Remote Code-Execution on NGINX Servers
2019-10-28 16:18

CVE-2019-11043 is trivial to exploit -- and a proof of concept is available.

PHP RCE flaw actively exploited to pop NGINX servers
2019-10-28 12:24

A recently patched vulnerability (CVE-2019-11043) in PHP is being actively exploited by attackers to compromise NGINX web servers, threat intelligence firm Bad Packets has confirmed. For a...

New PHP Flaw Could Let Attackers Hack Sites Running On Nginx Servers
2019-10-26 19:04

If you're running any PHP based website on NGINX server and have PHP-FPM feature enabled for better performance, then beware of a newly disclosed vulnerability that could allow unauthorized...

Multiple Code Execution Flaws Found In PHP Programming Language
2019-09-06 11:19

Maintainers of the PHP programming language recently released the latest versions of PHP to patch multiple high-severity vulnerabilities in its core and bundled libraries, the most severe of which...

Trakt app users' personal data exposed: We were hit by a 'PHP exploit'... back in 2014
2019-02-07 10:46

No payment info, but users' names, locations, email addies etc all 'lost' Trakt, the makers of an app that monitors users' TV programme and movie viewing habits, has 'fessed up to falling victim...

PHP PEAR supply chain attack: Backdoor added to installer
2019-01-24 12:57

Some additional details have emerged about the recent security breach involving the PHP PEAR (PHP Extension and Application Repository) webserver, but much is still unknown. What happened? The...

Someone Hacked PHP PEAR Site and Replaced the Official Package Manager
2019-01-23 09:48

Beware! If you have downloaded PHP PEAR package manager from its official website in past 6 months, we are sorry to say that your server might have been compromised. Last week, the maintainers at...

WordPress to Warn on Outdated PHP Versions
2019-01-16 15:41

In an effort to improve the security of websites, WordPress will display a warning starting in April 2019 when encountering outdated PHP versions. In December last year, the free and open-source...