Roughly 90 percent of all the hacked content management systems (CMSs) Sucuri investigated and helped fix in 2018 were WordPress sites. In a distant second, third, and fourth came Magento (4.6 percent), Joomla (4.3 percent), and Drupal (3.7 percent), according to a report the company published yesterday. . Sucuri experts blamed most of the hacks on vulnerabilities in plugins and themes, misconfiguration issues, and a lack of maintenance by webmasters, who often forgot to update their CMS, themes, and plugins. The link for this article located at ZDNet is no longer available. . Sucuri experts blamed most of the hacks on vulnerabilities in plugins and themes, misconfiguration i. roughly, percent, hacked, content, management, systems, (cmss), sucuri, investigated, helpe. . LinuxSecurity.com Team
The maintainers of WordPress announced a new version for the blogging platform, which is considered a critical security release that addresses a highly important cross-site scripting (XSS) vulnerability. . The XSS glitch affects all earlier versions of the content management system (CMS), and successful exploitation would allow a potential attacker to compromise a vulnerable website. The link for this article located at Softpedia is no longer available. . WordPress 5.6.3 resolves a significant vulnerability in cross-site scripting impacting all earlier content management system versions effectively.. WordPress Security,XSS Flaw Fix,Content Management System Update. . LinuxSecurity.com Team
The child-friendly Internet home of Ernie, Big Bird and Kermit the Frog went X-rate on Sunday as Sesame Street. According to security company Sophos, which noticed and took screenshots of the unsavoury event, the porn stayed live on the channel for around 20 minutes before Google itself took issue with the content, suspending it for "repeated or severe violations of our Community Guidelines." In the circumstances, the suspension was a blessing in an attack that also saw the show The link for this article located at Tech World is no longer available. . A startling incident unfolded when the Sesame Street broadcast was mysteriously taken over, revealing significant weaknesses in content oversight and digital safety protocols.. Content Management, Online Threats, Digital Safety. . LinuxSecurity.com Team
The US government has released open source code that it has been working on. In an unusual move for government transparency, the White House is letting developers get their mitts on its open source code. The US executive branch has been working on its custom code as part of its ongoing efforts to "develop an open platform for Whitehouse.gov.". "This code is available for anyone to review, use, or modify. We're excited to see how developers across the world put our work to good use in their own applications," it announced. The code is part of the Drupal project, which is an open source content management system. The White House believes its own coders have added to Drupal functionality in three ways. Its team has released a scalability module called "Context HTTP Headers", which adds metadata to content. The link for this article located at The Inquirer is no longer available. . Federal authorities unveil open-source software initiatives for community use, improving tools with WordPress and fostering accountability.. Open Source Code, Transparency Initiative, Drupal Development, Government Projects. . Alex
Securing networks has rapidly taken center stage among most enterprises as the threat from increasingly sophisticated attacks becomes more complex and costly to manage. According to the research group IDC, enterprises worldwide spent an estimated $32.6Bn in 2005 on network security but are still faced with an ever-changing landscape of new security threats. Traditional network defense solutions such as firewalls and intrusion prevention devices must be supplemented by secure content management devices in order to block the full range of sophisticated attacks including viruses, spyware, spam and phishing. . The link for this article located at IT Observer - Mark is no longer available. . Organizations encounter a shifting risk environment, requiring enhanced cybersecurity measures and strategies.. Enterprise Security, Network Defense, New Security Threats. . Anthony Pell
Hackers have compromised the download server for the open source PostNuke content management system, redirecting users to malicious code in place of the .zip download of the PostNuke program. The hacked code was distributed for more than 32 hours before PostNuke site maintainers addressed the security breach. . . .. Hackers have compromised the download server for the open source PostNuke content management system, redirecting users to malicious code in place of the .zip download of the PostNuke program. The hacked code was distributed for more than 32 hours before PostNuke site maintainers addressed the security breach. PostNuke users who installed a zip archive downloaded between 11:50 pm Sunday night and 8:30 a.m. today face a grim scenario. According to a statement on the PostNuke site, all data submitted during the installation - including the server name, database credentials, admin name and password - were likely sent to the hackers. In addition, "in one file there was code allowing a malicious user to execute any shell command on the web server." Either scenario would allow the attackers to gain control of the site where PostNuke was installed. The tar.gz download file was not affected. The tar format is traditionally used by Unix and Linux, while Zip is the leading Windows archive format. The link for this article located at Netcraft.com is no longer available. . The download server for PostNuke, an open source CMS, has been hacked, spreading malicious code to users.. PostNuke Exploit, Malicious Code, Server Breach, Open Source Management. . LinuxSecurity.com Team
FT. LAUDERDALE, Fla.--(BUSINESS WIRE)--Sept. 21, 2004--As reported last week, hackers are scheming about how to exploit the latest announced vulnerability in a number of Microsoft(R) operating systems and applications, including Microsoft Office(R) and several versions of Internet Explorer. . . .. FT. LAUDERDALE, Fla.--(BUSINESS WIRE)--Sept. 21, 2004--As reported last week, hackers are scheming about how to exploit the latest announced vulnerability in a number of Microsoft(R) operating systems and applications, including Microsoft Office(R) and several versions of Internet Explorer. The newly reported weakness allows malignant JPEG images to enter users' computers undetected via e-mail, Web site and instant message downloads, enabling an attacker to gain control of the computer. CyberGuard Corporation (Nasdaq:CGFW), the technology leader in network security, prevents attacks that might leverage the imaging vulnerability with its Webwasher Content Security Management (CSM) solution. Webwasher's CSM solution has built-in provisions that defend against new threats from file types that have previously been considered "harmless." On Friday, September 17, CyberGuard's Webwasher activated deep file inspection for JPEG files. Within minutes, Webwasher customers around the world were protected via their next automatic security update of any Webwasher product. The link for this article located at BusinessWire is no longer available. . DataShield's ImageProtector counters GIF vulnerabilities, effectively reducing exposure from harmful assets promptly.. CyberGuard Webwasher,JPEG Exploit Prevention,Network Threat Mitigation,Content Security Management. . LinuxSecurity.com Team
DRM: Digital Rights Management. Or, as some prefer to call it, Digital Restrictions Management. Basically, the idea is that the creators, and/or owners, of digital content - a song, a video, a document, even an email - should be able to . . . . DRM: Digital Rights Management. Or, as some prefer to call it, Digital Restrictions Management. Basically, the idea is that the creators, and/or owners, of digital content - a song, a video, a document, even an email - should be able to dictate how that content is used and who can use it. It's an issue that security pros need to be intimately familiar with. In February, Microsoft announced that it is getting into the DRM business. In typical Microsoft fashion, they'll cover everything. Your servers: Windows Rights Management Services (RMS). Your workstations: Windows Rights Management client. Your Web browser: Rights Management Add-On for Internet Explorer. Your CDs, movie files, and MP3s: Windows Media DRM. Your Office suite: IRM, or Information Rights Management, for Word, Excel, PowerPoint, and Outlook. It's all covered. Covered like a carpet bombing. The link for this article located at SecurityFocus is no longer available. . DRM: Digital Rights Management. Or, as some prefer to call it, Digital Restrictions Management. Basi. digital, management, rights, prefer, restrictions. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.