Wordfence Intelligence Weekly WordPress Vulnerability Report (September 30, 2024 to October 6, 2024)

_ Calling all superheroes and haunters! Introducing the Cybersecurity Month Spooktacular Haunt and the WordPress Superhero Challenge for the Wordfence Bug Bounty Program! Through November 11th, 2024: ...

Continue Reading
OpenAI Blocks 20 Global Malicious Campaigns Using AI for Cybercrime and Disinformation

OpenAI on Wednesday said it has disrupted more than 20 operations and deceptive networks across the world that attempted to use its platform for malicious purposes since the start of the year. This ac ...

Continue Reading
CVE-2024-9685 Notification for Telegram <= 3.3.1 – Missing Authorization to Authenticated (Subscriber+) Send Telegram Test Message

The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up to, ...

Continue Reading
CVE-2024-9798 Health endpoint offers list of onboarded services to unauthenticated users

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for...Read More ...

Continue Reading
Beyond the Edge: Complementing WAAP with Always-On API Security

Learn best practices for API security ? and explore why WAAP on its own isn?t...Read More ...

Continue Reading
Android GKI Kernels Use-After-Free

...Read More ...

Continue Reading
CVE-2024-9802 Conformance validation endpoint discloses detail about service to unauthenticated users

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endp ...

Continue Reading
CVE-2024-48902

In JetBrains YouTrack before 2024.3.46677 improper access control allowed users with project update permission to delete applications via...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: