w

Interpol Issues Arrest Warrant For Fake Passport Hit Team




w

Hackers Expose Security Flaws With Elvis Presley Passport




w

WordPress WooCommerce CardGate Payment Gateway 3.1.15 Bypass

WordPress WooCommerce CardGate Payment Gateway plugin version 3.1.15 suffers from a payment process bypass vulnerability.




w

Magento WooCommerce CardGate Payment Gateway 2.0.30 Bypass

Magento WooCommerce CardGate Payment Gateway version 2.0.30 suffers from a payment process bypass vulnerability.




w

TP-Link TL-WR849N 0.9.1 4.16 Authentication Bypass

TP-Link TL-WR849N version 0.9.1 4.16 suffers from a firmware upload authentication bypass vulnerability.




w

Intelbras Wireless N 150Mbps WRN240 Authentication Bypass

Intelbras Wireless N 150Mbps WRN240 suffers from a configuration upload authentication bypass vulnerability.




w

Citrix Gateway 11.1 / 12.0 / 12.1 Cache Bypass

Citrix Gateway versions 11.1, 12.0, and 12.1 suffer from a caching bypass vulnerability.




w

Ivanti Workspace Manager Security Bypass

Ivanti Workspace Manager versions prior to 10.3.90 suffer from a bypass vulnerability.




w

Oce Colorwave 500 CSRF / XSS / Authentication Bypass

Oce Colorwave 500 printer suffers from authentication bypass, cross site request forgery, and cross site scripting vulnerabilities.




w

Huawei HG630 2 Router Authentication Bypass

Huawei HG630 2 Router suffers from an authentication bypass vulnerability.




w

Nissan Car Secretly Shares Driver Data With Websites




w

IBM Data Risk Manager 2.0.3 Default Password

This Metasploit module abuses a known default password in IBM Data Risk Manager. The a3user has the default password idrm and allows an attacker to log in to the virtual appliance via SSH. This can be escalate to full root access, as a3user has sudo access with the default password. At the time of disclosure, this is a 0day. Versions 2.0.3 and below are confirmed to be affected, and the latest 2.0.6 is most likely affected too.






w

Multiple Vulnerabilities in MySQL - Upgrade Now





w

netABuse Insufficient Windows Authentication Logic Scanner

netABuse is a scanner that identifies systems susceptible to a Microsoft Windows insufficient authentication logic flaw.







w

WebAssembly Changes Could Ruin Meltdown And Spectre Patches




w

New Spectre Attack Enables Secrets To Be Leaked Over A Network









w

Lenovo Patches Intel Firmware Flaws In Multiple Product Lines




w

Intel Patches High-Severity Flaws In Media SDK, Mini PC




w

Intel Fixes Severe NUC Firmware, Web Console Vulnerabilities







w

Intel CMSE Bug Is Worse Than Previously Thought




w

Intel Fixes High-Severity Flaws In NUC, Discontinues Buggy Compute Module




w

RIAA Wants Infamous File-Sharer To Campaign Against Piracy














w

uTorrent Users Urged To Upgrade To Mitigate Hijacking Flaw





w

WordPress WooCommerce Advanced Order Export 3.1.3 Cross Site Scripting

WordPress WooCommerce Advanced Order Export plugin version 3.1.3 suffers from a cross site scripting vulnerability.




w

WebTareas 2.0p8 Cross Site Scripting

WebTareas version 2.0p8 suffers from a cross site scripting vulnerability.