Vulnerabilities — Page 6

Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Zimbra Patches Critical Webmail Flaw That Lets Booby-Trapped Emails Run Code
A stored cross-site scripting bug in Zimbra's Classic Web Client can hijack a user's session the moment a rigged email is opened.

Six bugs in U-Boot bootloader open the door to hidden firmware attacks
Researchers found flaws in the open-source code that starts up millions of embedded devices, from routers to industrial kit. Fixes are out.

Six New Bugs in U-Boot Could Let Attackers Hijack Devices at Startup
Binarly researchers found flaws in the tiny program that boots routers, cameras and server chips. Two of them could let intruders run their own code before the device even wakes up.

Progress tells ShareFile customers to pull the plug amid 'credible' threat
The maker of a widely used file-sharing tool is emailing on-premises customers to shut down their servers now, while it investigates what it calls a credible external threat.

Nine Security Flaws Found in ATM Encryption Software, and Nobody Agrees How Bad It Is
A researcher found serious bugs in software that locks ATM hard drives. The world's biggest ATM maker says they don't matter. The researcher disagrees. The truth is somewhere uncomfortable.

Laser Pulse Cracks Tangem Crypto Card Password in Seconds
Ledger's Donjon team showed a targeted laser can wipe the PIN on a Tangem wallet card, handing full control to whoever holds it.

Free Android VPNs Are Leaking Your Traffic, Study of 281 Apps Finds
Researchers tested the most popular free VPN apps on Google Play. Many fail at the one job they promise: keeping your internet activity private.

Unpatched Flaw in Alibaba's XQUIC Lets Anyone Crash HTTP/3 Servers With 260 Bytes
A researcher at FoxIO disclosed the bug on 8 July. There is no fix, no login required, and no malformed packets involved.

'Ill Bloom' Wallet Flaw Drains $3.1 Million as Weak Recovery Phrases Give Thieves the Keys
Security firm Coinspect says attackers are already sweeping wallets whose recovery words were generated with predictable randomness.

Security Debt Is Growing Faster Than Companies Can Fix It. Here Is What That Means.
Eight in ten organisations are sitting on a backlog of unresolved security flaws that stretch back more than a year. A practical framework, first outlined in CSO Online, explains how to turn that problem into a board-level conversation.

Microsoft Patches 'RoguePlanet' Defender Flaw a Month After Public Disclosure
The privilege escalation bug in the Malware Protection Engine sat exposed for weeks before Redmond shipped a fix.

Google Patches 27 Chrome Flaws, Two Rated Critical
Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

Microsoft patches 'RoguePlanet' Defender flaw after researcher publishes exploit in disclosure spat
The zero-day let attackers hand themselves the keys to a fully patched Windows machine. It was revealed by a researcher publicly feuding with Microsoft.

A Secret Backdoor in Tenda Home Routers Lets Strangers Take Control, and There Is No Fix
A hidden login trick buried in Tenda networking gear gives anyone who knows the magic password full administrative control. The maker has not responded, and no patch exists.