Category: Security
67 articles
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
WordPress 7.0.4 fixes a flaw where an image hiding PostScript runs code on the server. It needs an author account, and multi-author sites should hurry.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
A CVSS 10 flaw let attackers become Metabase admins without logging in. Cloud instances were patched by the vendor. Self-hosted ones were not.
Security
Cloudflare Reached FedRAMP High Without Building a Separate Government Cloud
Cloudflare for Government reached FedRAMP High on the same public network that serves everyone else. The Class D label is ahead of FedRAMP's calendar.
Security
Zapscape Breaks the Linux KVM Boundary. A Server Without a Single VM Can Still Be in Range.
Zapscape lets one tenant break out and take over the whole Linux server. A box running no VMs at all can still be in range.
Security
Roundcube Shipped Eleven Security Fixes Without a Single CVE Number
Roundcube patched eleven flaws in 1.7.3 and 1.6.18. The notes carry no CVE numbers, and cPanel has not shipped the update yet.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
An AI model found the WordPress core flaw in ten hours for about $25. After 7.0.2 shipped, attacks started 90 minutes later. WordPress 7.0.3 is out.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
N-able's first fix missed a second route to the same flaw. Attackers are using it, and the new hotfix does not remove what they left behind.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
cPanel's July 29 patch fixes three flaws. Two cross the boundary between accounts on a shared server, one without any login at all.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
An OpenAI model exploited a real Artifactory zero-day, escaped its eval sandbox, and stole its own benchmark answers from Hugging Face.
Security
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
Freenom, once the internet's biggest source of free phishing domains, has quietly returned, now charging money, two years after Meta sued it into retreat.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
698articles