Critical Flaw Uncovered in WordPress Backup Plugin Used by Over 3 Million Sites

Blog WriterThe Hacker News - Original news source is thehackernews.com

Patches have been issued to contain a “severe” security vulnerability in UpdraftPlus, a WordPress plugin with over three million installations, that can be weaponized to download the site’s private data …

New Linux Privilege Escalation Flaw Uncovered in Snap Package Manager

Blog WriterThe Hacker News - Original news source is thehackernews.com

Multiple security vulnerabilities have been disclosed in Canonical’s Snap software packaging and deployment system, the most critical of which can be exploited to escalate privilege to gain root privileges. Snaps are self-contained …

Microsoft Warns of ‘Ice Phishing’ Threat on Web3 and Decentralized Networks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has warned of emerging threats in the Web3 landscape, including “ice phishing” campaigns, as a surge in adoption of blockchain and DeFi technologies emphasizes the need to build security into the …

Another Critical RCE Discovered in Adobe Commerce and Magento Platforms

Blog WriterThe Hacker News - Original news source is thehackernews.com

Adobe on Thursday updated its advisory for an actively exploited zero-day affecting Adobe Commerce and Magento Open Source to patch a newly discovered flaw that could be weaponized to achieve arbitrary code …

Attackers Can Crash Cisco Email Security Appliances by Sending Malicious Emails

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cisco has released security updates to contain three vulnerabilities affecting its products, including one high-severity flaw in its Email Security Appliance (ESA) that could result in a denial-of-service (DoS) condition …

Iranian Hackers Targeting VMware Horizon Log4j Flaws to Deploy Ransomware

Blog WriterThe Hacker News - Original news source is thehackernews.com

A “potentially destructive actor” aligned with the government of Iran is actively exploiting the well-known Log4j vulnerability to infect unpatched VMware Horizon servers with ransomware. Cybersecurity firm SentinelOne dubbed the group “TunnelVision” …

U.S. Says Russian Hackers Stealing Sensitive Data from Defense Contractors

Blog WriterThe Hacker News - Original news source is thehackernews.com

State-sponsored actors backed by the Russian government regularly targeted the networks of several U.S. cleared defense contractors (CDCs) to acquire proprietary documents and other confidential information pertaining to the country’s …

VMware Issues Security Patches for High-Severity Flaws Affecting Multiple Products

Blog WriterThe Hacker News - Original news source is thehackernews.com

VMware on Tuesday patched several high-severity vulnerabilities impacting ESXi, Workstation, Fusion, Cloud Foundation, and NSX Data Center for vSphere that could be exploited to execute arbitrary code and cause a denial-of-service (DoS) condition. …