XSS Vulnerability in Yoast SEO Plugin Endangers Over 5 Million WordPress Websites
Security researcher Bassem Essam uncovered a critical cross-site scripting (XSS) vulnerability in the widely-used Yoast SEO WordPress plugin, potentially jeopardizing over 5 million websites. XSS Vulnerability in Yoast SEO Plugin [...]
Trend Micro Antivirus One Allowed Malicious Code Injection by Attackers
A major update for Trend Micro's Antivirus One software has been launched. This update tackles a critical vulnerability that could have allowed attackers to inject malicious code. The vulnerability, named [...]
MITRE Exposes Chinese Hackers’ Employment of ROOTROT Webshell in Network Breach
The MITRE Corporation, a non-profit organization managing research and development centers for the U.S. government, has revealed a recent infiltration by sophisticated nation-state hackers into one of its internal research [...]
A novel Cuckoo malware strain is targeting macOS users
Researchers have unveiled a new malware strain named "Cuckoo," combining features of spyware and infostealers, designed to target both Intel and ARM-based Macs, employing advanced methods to extract sensitive data. [...]
ShadowSyndicate hackers exploit Aiohttp vulnerability for sensitive data theft
A directory traversal vulnerability (CVE-2024-23334) in aiohttp versions before 3.9.2 permits remote attackers to access sensitive files on the server by bypassing file reading validation within the root directory when [...]