Tag: Open Source Software
-
Critical WordPress Post SMTP Plugin Vulnerability Puts 400,000 Sites at Risk of Account Takeover
A critical vulnerability has been discovered in the Post SMTP WordPress plugin, affecting over 400,000 active installations across the web. …
-
MIT Sloan quietly shelves AI ransomware study after researcher calls BS
Do 80 percent of ransomware attacks really come from AI? MIT Sloan has now withdrawn a working paper that made that eyebrow-raising claim …
-
Top security researcher shares their bug bounty process
As we wrap Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to spotlight another top performing security researcher who …
-
CVE-2025-61780 (rack): Rack has a Possible Information Disclosure Vulnerability
ADVISORIES CVE-2025-61780 (NVD) GHSA-r657-rxjc-j557 Vendor Advisory GEM rack SEVERITY CVSS v3.x: 5.8 (Medium) PATCHED VERSIONS ~> 2.2.20 ~> …
-
7-Zip Vulnerabilities Allowing Remote Code Execution
Two critical vulnerabilities in 7-Zip’s handling of ZIP archives have emerged, enabling remote attackers to execute arbitrary code by …
-
Lightship Security and the OpenSSL Corporation Submit OpenSSL 3.5.4 for FIPS 140-3 Validation
Lightship Security, an Applus+ Laboratories company and accredited cryptographic security test laboratory, and the OpenSSL Corporation, the …
-
The Ultimate WordPress Security Guide
Cheap shared hosting is popular. Thousands of people have started their own websites with a modest investment in …
-
OpenSSH ProxyCommand Flaw Allows Remote Code Execution – PoC Released
Security researchers have uncovered a critical flaw in OpenSSH’s ProxyCommand feature that can be leveraged to achieve remote code …
-
Red Hat fesses up to GitLab breach after attackers brag of data theft
What started as cyber crew bragging has now been confirmed by Red Hat: someone gained access to its consulting GitLab system and walked …
-
OpenSSL 3.6.0: New features, crypto support
The OpenSSL Project has announced the release of OpenSSL 3.6.0, a feature update that brings significant functionality improvements, …
-
Nosey Parker: Open-source tool finds sensitive information in textual data and Git history
Nosey Parker is an open-source command-line tool that helps find secrets and sensitive information hidden in text files. It works like a …
-
After Shai-Hulud, GitHub tightens npm publishing security
Attackers are constantly finding ways to take over accounts and push malicious packages to the npm registry, the (GitHub-operated) online …
●●●
