Podcast Episode 28: Zoom Zero-Day Vulnerability, WP Engine Buys Flywheel, and Other News

https://www.wordfence.com/blog/2019/07/podcast-episode-28-zoom-zero-day-vulnerability-wp-engine-buys-flywheel-and-other-news/ A security researcher found vulnerabilities in the Mac client for Zoom, a popular video conferencing application. After 90 days and two weeks, the vulnerability still exists. Mitigating the vulnerability entails typing the following commands in terminal, replacing [pid] with the process ID: $> lsof -i :19421 $> kill -9 [pid] $> rm -rf ~/.zoomus […] More info: https://www.wordfence.com/blog/2019/07/podcast-episode-28-zoom-zero-day-vulnerability-wp-engine-buys-flywheel-and-other-news/

Icegram Persistent Cross-Site Scripting

http://feedproxy.google.com/~r/sucuri/blog/~3/f5r1d599CaA/icegram-persistent-cross-site-scripting.html Icegram is a plugin that helps you collect email addresses for your newsletter. Other features include light-box popup offers, header action bars, toast notifications, and slide-in messengers. Versions 1.10.28.2 and lower are affected by a persistent Cross-Site Scripting in the admin area. This plugin has over 40,000 installations and any attacker with a subscriber […] More info: http://feedproxy.google.com/~r/sucuri/blog/~3/f5r1d599CaA/icegram-persistent-cross-site-scripting.html
Translate »