Skip to content
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap
GeekWire
GeekWire
  • HOME
  • NEWS
    • CERT
    • EXPLOITS
    • NCSC
    • NVD
    • SECURELIST
    • US-CERT
  • BLOG
    • Books
    • OSINT
    • Pentest
    • Privacy
  • GHDB
  • CHDB
  • OSINT
  • LABS
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

Web Development

SHA-3 code execution bug patched in PHP – check your version!

1 November 2022

You’ve probably seen story after story in the media in the past week about a critical bug in OpenSSL, though at the time of writing this …

Tags Cryptography, PHP, Programming, Programming Languages, Web Development

Almost 1/3 of Top npm Accounts Aren’t Protected with 2FA

7 April 2022

The npm JavaScript package manager and default package manager for the JavaScript runtime environment Node.js is insanely popular. It’s …

Tags Accounts, IT, Open Source, Open Source Software, Web Development

ZetaChain Offers Bridgeless Blockchain Interconnectivity

10 March 2022

One fundamental challenge for decentralized application (dApp) development is the fact that individual blockchains are not interoperable by …

Tags Blockchains, IT, Offers, Open Source, Web Development

Irony alert! PHP fixes security flaw in input validation code

18 February 2022

If you’re using PHP in your network, check that you’re using the latest version, currently 8.1.3. Released yesterday [2022-02-17], this …

Tags IT, PHP, Programming, Programming Languages, Web Development

Missouri will not prosecute ‘hacker’ reporter for daring to view state website HTML

17 February 2022

The State of Missouri will not prosecute a journalist branded a “hacker” for viewing website source code and reporting a serious security …

Tags HTML, IT, Missouri, News, Web Development

Journalist won’t be indicted for hacking for viewing a state website’s HTML

16 February 2022

A journalist incorrectly branded as a “hacker” by the governor of Missouri won’t be prosecuted “for hacking”. This was a quick …

Tags Cyber Threats, Hacking, HTML, Journalists, Web Development

PHP Everywhere code execution bugs impact thousands of WordPress websites

10 February 2022

Critical remote code execution (RCE) vulnerabilities in a popular WordPress plugin have been made public. The RCE bugs impact PHP …

Tags IT, PHP, Programming, Programming Languages, Web Development

PHP Everywhere RCE flaws threaten thousands of WordPress sites

9 February 2022

Researchers found three critical remote code execution (RCE) vulnerabilities in the ‘PHP Everywhere’ plugin for WordPress, used by over …

Tags IT, PHP, Programming, Programming Languages, Web Development

Evasive maneuvers: HTML smuggling explained

15 November 2021

Microsoft Threat Intelligence Center (MSTIC) last week disclosed “a highly evasive malware delivery technique that leverages legitimate …

Tags Explained, HTML, HTML smuggling, IT, Web Development

Microsoft warns of surge in HTML smuggling phishing attacks

12 November 2021

Microsoft has seen a surge in malware campaigns using HTML smuggling to distribute banking malware and remote access trojans (RAT). While …

Tags HTML, IT, News, Web Development

Token Based Security: Angular Applications, Part 3

22 October 2021

Introduction In the previous post of this series, we configured our Angular application as a client of IdnentityServer and completed the …

Tags Angular Applications, IT, News, Tokens, Web Development

Token Based Security: Angular Applications, Part 2

15 October 2021

Introduction In the previous post on the topic of Token Based Security, we created an API endpoint and protected it (using Authorize …

Tags Angular Applications, IT, News, Tokens, Web Development

Token-based Security: Angular Applications – Part 1

9 October 2021

Introduction I have written few posts on token-based security, its importance, OAuth, OIDC, and Identity-Server. You can check the previous …

Tags Angular Applications, IT, News, Web Development

 Cisco Releases Security Updates

22 July 2021

Cisco has released security updates to address multiple vulnerabilities in Intersight Virtual Appliance. An attacker could exploit these …

Tags Content-management Framework, Drupal, Open Source, Open Source Software, Web Development
Older posts
Page1 Page2 … Page64 Next →
Cookie-Free

NVD

  • CVE-2023-24060 – Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functiona …27 January 2023
  • CVE-2023-22740 – Discourse is an open source platform for community discussion. Versions prior to 3.1.0.bet …27 January 2023
  • CVE-2020-36659 – In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not chec …27 January 2023
  • CVE-2020-36658 – In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by d …27 January 2023
  • CVE-2022-40718 – This vulnerability allows network-adjacent attackers to execute arbitrary code on affected …26 January 2023
  • CVE-2022-40719 – This vulnerability allows network-adjacent attackers to execute arbitrary commands on affe …26 January 2023

EXPLOITS

  • Feehi CMS 2.1.1 – Remote Code Execution (Authenticated)22 November 2022
  • SmartRG Router SR510n 2.6.13 – Remote Code Execution22 November 2022
  • CVAT 2.0 – Server Side Request Forgery18 November 2022
  • MSNSwitch Firmware MNT.2408 – Remote Code Execution18 November 2022
  • Open Web Analytics 1.7.3 – Remote Code Execution18 November 2022
  • IOTransfer V4 – Unquoted Service Path11 November 2022

SECURELIST

  • What your SOC will be facing in 202323 January 2023
  • Roaming Mantis implements new DNS changer in its malicious mobile app in 202219 January 2023
  • What threatens corporations in 2023: media blackmail, fake leaks and cloud attacks18 January 2023
  • How much security is enough?9 January 2023
  • BlueNoroff introduces new methods bypassing MoTW27 December 2022
  • Ransomware and wiper signed with stolen certificates22 December 2022
Copyright © 2023 GeekWire | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.
Next Page »