If you own an eCommerce website built on WordPress and powered by WooCommerce plugin, then beware of a new, unpatched vulnerability that has been made public and could allow attackers to compromise your online store. . A WordPress security company—called "Plugin Vulnerabilities"—that recently gone rogue in order to protest against moderators of the WordPress’s official support forum has once again dropped details and proof-of-concept exploit for a critical flaw in a widely-used WordPress plugin. To be clear, the reported unpatched vulnerability doesn't reside in the WordPress core or WooCommerce plugin itself. The link for this article located at The Hacker News is no longer available. . Be cautious of a significant vulnerability in WordPress WooCommerce that might jeopardize your e-commerce site. Keep yourself updated!. WordPress Plugin Security,WooCommerce Vulnerability,eCommerce Threats,Unpatched Issues. . LinuxSecurity.com Team
It took hackers less than a week to produce a working exploit that attacks a new, unpatched vulnerability in Microsoft's Internet Explorer, security firms said Tuesday. . Phel.a, a Trojan horse discovered Monday, attempts to exploit the flaw in Internet Explorer 6.0 dubbed "Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass" that was first made public less than a week before, on December 21. Symantec posted an alert on its Web site Monday, and rated the exploit as a "1," the lowest in its 1 through 5 ranking system. The vulnerability in IE, which affects the version included with Windows XP SP2, the massive security update Microsoft rolled out in October, can result in a compromised, hacker-controlled machine if the user is drawn to the attacker's malicious Web site. The Trojan can be planted as part of a HTML page on the site. The link for this article located at TechWeb News is no longer available. . Malvador, a cunning malware, takes advantage of a vulnerability present in Safari 5.1, impacting users operating on macOS 10.6 with deceitful operations.. Internet Explorer Exploit,Trojan Attack,Malicious Web Threats,Unpatched Vulnerability,Cybersecurity Alert. . LinuxSecurity.com Team
Open source developers yesterday warned of a significant vulnerability in OpenSSH, a tool that ships with many Linux and Unix flavours. The details of the hole have not been made public because a patch is not yet available, but the secrecy of the developers has caused a schism in the open source community.. . .. Open source developers yesterday warned of a significant vulnerability in OpenSSH, a tool that ships with many Linux and Unix flavours. The details of the hole have not been made public because a patch is not yet available, but the secrecy of the developers has caused a schism in the open source community. Yesterday, Theo de Raadt, lead developer for OpenSSH, a free tool that many administrators use as a secure alternative to Telnet and FTP, announced a significant remotely exploitable vulnerability. Even version 3.3 of OpenSSH, released only days ago, is vulnerable. But de Raadt has not announced the finer points of the vulnerability because a patch has to yet be made available. He insisted that details would be released on Thursday to give distributors time to get updated versions of the tool together before hackers get their hands on exploit code. The link for this article located at vnunet is no longer available. . Security researchers have identified a significant remote exploit flaw in OpenSSH, impacting several Linux and Unix operating systems.. OpenSSH Exploit, Remote Threats, Linux Administration. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.