Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

PHP

QNAP warns of a critical PHP flaw that could lead to remote code execution

23 June 2022

Taiwanese company QNAP is addressing a critical PHP vulnerability that could be exploited to achieve remote code execution. Taiwanese …

Tags Computer Hardware, Critical, Devices, NAS, PHP

Hijacking of popular ctx and phpass packages reveals open source security gaps

26 May 2022

The Python module “ctx” and a fork of the PHP library “phpass” have recently been modified by an unknown attacker to grab AWS …

Tags Hijacking, IT, PHP, PyPI, Python

FBI warns of scraping attacks targeting online checkout pages

18 May 2022

The U.S. Federal Bureau of Investigation has issued a flash alert warning businesses that cybersecurity actors are scraping credit card …

Tags Cyber, IT, Magecart, PHP, Programming

FBI: Hackers used malicious PHP code to grab credit card data

17 May 2022

The Federal Bureau of Investigations (FBI) is warning that someone is scraping credit card data from the checkout pages of US businesses’ …

Tags Cyber Threats, FBI, Hacking, IT, PHP

15-Year-old Security Vulnerability In The PEAR PHP Repository Permits Supply Chain Attack

5 April 2022

PEAR PHP repository has been found to contain a 15-year-old security vulnerability that could provide an attacker with the ability to carry …

Tags Cyber Attack, PHP, Programming, Programming Languages, Repository

15-Year-Old Bug in PEAR PHP Repository Could’ve Enabled Supply Chain Attacks

2 April 2022

A 15-year-old security vulnerability has been disclosed in the PEAR PHP repository that could permit an attacker to carry out a supply …

Tags Bug, IT, PHP, Programming, Repository

Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

16 March 2022

Researchers have disclosed an unpatched security vulnerability in “dompdf,” a PHP-based HTML to PDF converter, that, if successfully …

Tags Bug, HTML, PHP, Programming, Programming Languages

Irony alert! PHP fixes security flaw in input validation code

18 February 2022

If you’re using PHP in your network, check that you’re using the latest version, currently 8.1.3. Released yesterday [2022-02-17], this …

Tags IT, PHP, Programming, Programming Languages, Web Development

PHP Everywhere code execution bugs impact thousands of WordPress websites

10 February 2022

Critical remote code execution (RCE) vulnerabilities in a popular WordPress plugin have been made public. The RCE bugs impact PHP …

Tags IT, PHP, Programming, Programming Languages, Web Development

PHP Everywhere RCE flaws threaten thousands of WordPress sites

9 February 2022

Researchers found three critical remote code execution (RCE) vulnerabilities in the ‘PHP Everywhere’ plugin for WordPress, used by over …

Tags IT, PHP, Programming, Programming Languages, Web Development

WordPress News » Security: WordPress 5.7.2 Security Release

13 May 2021

WordPress 5.7.2 is now available. This security release features one security …

Tags IT, PHP, Programming, Programming Languages, Releases

PHP Composer Flaw That Could Affect Millions of Sites Patched

5 May 2021

A patch has been issued for a serious vulnerability that impacts PHP Composer – a tool to manage and install software dependencies in the …

Tags Composer, Flaws, PHP, Programming, Programming Languages

PHP community sidesteps its third supply chain attack in three years

30 April 2021

Swiss cybersecurity researchers recently found security holes in Composer, the software tool that programming teams use to access …

Tags Composer, Packagist, PHP, Programming, Programming Languages

Command injection flaw in PHP Composer allowed supply-chain attacks

29 April 2021

A vulnerability in the PHP Composer could have allowed an attacker to execute arbitrary commands and backdoor every PHP package. The …

Tags Composer, PHP, Programming, Programming Languages, Web Development
Post navigation
Older posts
Page1 Page2 … Page7 Next →
Cookie-Free

NVD

  • CVE-2022-34835 – In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based b …30 June 2022
  • CVE-2017-20121 – A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as cr …30 June 2022
  • CVE-2017-20122 – A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Aff …30 June 2022
  • CVE-2017-20123 – A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This aff …30 June 2022
  • CVE-2017-20124 – A vulnerability classified as critical has been found in Online Hotel Booking System Pro P …30 June 2022
  • CVE-2017-20125 – A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. A …30 June 2022

EXPLOITS

  • Mailhog 1.0.1 – Stored Cross-Site Scripting (XSS)28 June 2022
  • WSO2 Management Console (Multiple Products) – Unauthenticated Reflected Cross-Site Scripting (XSS)28 June 2022
  • WordPress Plugin Weblizar 8.9 – Backdoor28 June 2022
  • Virtua Software Cobranca 12S – SQLi14 June 2022
  • Marval MSM v14.19.0.12476 – Cross-Site Request Forgery (CSRF)14 June 2022
  • Marval MSM v14.19.0.12476 – Remote Code Execution (RCE) (Authenticated)14 June 2022

SECURELIST

  • The SessionManager IIS backdoor30 June 2022
  • The SessionManager IIS backdoor: a possibly overlooked GELSEMIUM artefact30 June 2022
  • The hateful eight: Kaspersky’s guide to modern ransomware groups’ TTPs23 June 2022
  • APT ToddyCat21 June 2022
  • ‘Unpacking’ technical attribution and challenges for ensuring stability in cyb20 June 2022
  • How much does access to corporate infrastructure cost?15 June 2022

Information Cyber Network Enterprise Security News

Copyright © 2022 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.

GeekWire Information Cyber Network Enterprise Security News

Next Page »