Below I’ve curated cyber security news from the world-wide-web – the lefthand column is from “The Hacker News” website and on the right is news from “Security Week”. Both are top cyber security news sites. In the very least this shows that threats are daily and they are very real.
Hacker News
- NHIs Are the Future of Cybersecurity: Meet NHIDRby info@thehackernews.com (The Hacker News) on November 20, 2024 at 11:30 am
The frequency and sophistication of modern cyberattacks are surging, making it increasingly challenging for organizations to protect sensitive data and critical infrastructure. When attackers compromise a non-human identity (NHI), they can swiftly exploit it to move laterally across systems, […]
- Decades-Old Security Vulnerabilities Found in...by info@thehackernews.com (The Hacker News) on November 20, 2024 at 9:16 am
Multiple decade-old security vulnerabilities have been disclosed in the needrestart package installed by default in Ubuntu Server (since version 21.04) that could allow a local attacker to gain root privileges without requiring user interaction. The Qualys Threat Research Unit (TRU), which […]
- China-Backed Hackers Leverage SIGTRAN, GSM...by info@thehackernews.com (The Hacker News) on November 20, 2024 at 6:58 am
A new China-linked cyber espionage group has been attributed as behind a series of targeted cyber attacks targeting telecommunications entities in South Asia and Africa since at least 2020 with the goal of enabling intelligence collection. Cybersecurity company CrowdStrike is tracking the adversary […]
- Apple Releases Urgent Updates to Patch Actively...by info@thehackernews.com (The Hacker News) on November 20, 2024 at 4:37 am
Apple has released security updates for iOS, iPadOS, macOS, visionOS, and its Safari web browser to address two zero-day flaws that have come under active exploitation in the wild. The flaws are listed below - CVE-2024-44308 - A vulnerability in JavaScriptCore that could lead to arbitrary code […]
- Oracle Warns of Agile PLM Vulnerability Currently...by info@thehackernews.com (The Hacker News) on November 20, 2024 at 4:24 am
Oracle is warning that a high-severity security flaw impacting the Agile Product Lifecycle Management (PLM) Framework has been exploited in the wild. The vulnerability, tracked as CVE-2024-21287 (CVSS score: 7.5), could be exploited sans authentication to leak sensitive information. "This […]
- Ngioweb Botnet Fuels NSOCKS Residential Proxy...by info@thehackernews.com (The Hacker News) on November 19, 2024 at 2:01 pm
The malware known as Ngioweb has been used to fuel a notorious residential proxy service called NSOCKS, as well as by other services such as VN5Socks and Shopsocks5, new findings from Lumen Technologies reveal. "At least 80% of NSOCKS bots in our telemetry originate from the Ngioweb botnet, mainly […]
- Hackers Hijack Unsecured Jupyter Notebooks to...by info@thehackernews.com (The Hacker News) on November 19, 2024 at 2:00 pm
Malicious actors are exploiting misconfigured JupyterLab and Jupyter Notebooks to conduct stream ripping and enable sports piracy using live streaming capture tools. The attacks involve the hijack of unauthenticated Jupyter Notebooks to establish initial access, and perform a series of actions […]
- Privileged Accounts, Hidden Threats: Why...by info@thehackernews.com (The Hacker News) on November 19, 2024 at 11:30 am
Privileged accounts are well-known gateways for potential security threats. However, many organizations focus solely on managing privileged access—rather than securing the accounts and users entrusted with it. This emphasis is perhaps due to the persistent challenges of Privileged Access […]
- New 'Helldown' Ransomware Variant Expands Attacks...by info@thehackernews.com (The Hacker News) on November 19, 2024 at 9:40 am
Cybersecurity researchers have shed light on a Linux variant of a relatively new ransomware strain called Helldown, suggesting that the threat actors are broadening their attack focus. "Helldown deploys Windows ransomware derived from the LockBit 3.0 code," Sekoia said in a report shared with The […]
- Chinese Hackers Exploit T-Mobile and Other U.S....by info@thehackernews.com (The Hacker News) on November 19, 2024 at 7:02 am
U.S. telecoms giant T-Mobile has confirmed that it was also among the companies that were targeted by Chinese threat actors to gain access to valuable information. The adversaries, tracked as Salt Typhoon, breached the company as part of a "monthslong campaign" designed to harvest cellphone […]
WordPress News
- WordPress 6.7 “Rollins”by Matt Mullenweg on November 12, 2024 at 9:35 pm
WordPress 6.7, code-named 'Rollins,' celebrates legendary jazz saxophonist Sonny Rollins and debuts the sleek, versatile Twenty Twenty-Five theme, designed for any blog, any scale. Dive into new font management features and gain a macro perspective on your site with the Zoom Out feature. Embrace […]
- WordPress 6.7 Release Candidate 3by David Baumwald on November 5, 2024 at 5:02 pm
The third release candidate (RC3) for WordPress 6.7 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you evaluate […]
- WordPress 6.7 Release Candidate 2by David Baumwald on October 29, 2024 at 5:08 pm
The second release candidate (RC2) for WordPress 6.7 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- WordPress Community Creates 1,000 Block Themes in...by annezazu on October 23, 2024 at 5:01 pm
In nearly 1,000 days, the WordPress community has created 1,000 Block themes—coming together to use the full potential of the Site Editor and unleash new creative possibilities for everyone.
- WordPress 6.7 Release Candidate 1by David Baumwald on October 22, 2024 at 4:42 pm
The first release candidate (RC1) for WordPress 6.7 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you evaluate […]
- Expanding Our Code of Conduct to Protect Private...by Nicholas Garofalo on October 19, 2024 at 12:51 am
At the heart of our community is our shared pledge to create a space that is harassment-free, welcoming, and inclusive for all. Our Community Code of Conduct already outlines a clear set of expectations, while also providing examples of unacceptable actions. Today, we are reinforcing our values by […]
- WordPress Thanks Salesforceby Matt Mullenweg on October 18, 2024 at 8:17 pm
In the midst of our legal battles with Silver Lake and WP Engine, I wanted to take a moment to highlight something positive. Because of my friendships with the co-founders of Slack, Stewart Butterfield and Cal Henderson, WordPress.org has had a free version of the Pro version of Slack since they […]
- WP Engine Promotions & Couponsby WordPress.org on October 17, 2024 at 3:19 pm
Given the egregious legal attacks by WP Engine against WordPress co-founder Matt Mullenweg, a number of their customers have been looking for alternative hosting, and in return a number of hosts have created specials and promotions for WP Engine customers looking to migrate to a host that has great […]
- WordPress 6.7 Beta 3by David Baumwald on October 15, 2024 at 12:30 am
WordPress 6.7 Beta 3 is now ready for testing! This beta version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it is recommended you evaluate Beta 3 on a test server and site. You […]
- Secure Custom Fieldsby Matt Mullenweg on October 12, 2024 at 6:26 pm
On behalf of the WordPress security team, I am announcing that we are invoking point 18 of the plugin directory guidelines and are forking Advanced Custom Fields (ACF) into a new plugin, Secure Custom Fields. SCF has been updated to remove commercial upsells and fix a security problem. On October […]