POC Exploit Code Published for Critical Apache HugeGraph RCE Vulnerability

If you haven’t upgraded to version 1.3.0 of Apache HugeGraph, now is the time. At least two proof-of-concept (POC) exploits for a CVSS 9.8-rated remote command execution (RCE) vulnerability in the open-source graph database have been made public. Apache HugeGraph Continue reading POC Exploit Code Published for Critical Apache HugeGraph RCE Vulnerability

The Snowflake Attack Could Become One of the Largest Data Breaches in History

A cyberattack targeting customers of cloud storage provider Snowflake is rapidly escalating and may become one of the largest data breaches ever recorded. Last week, Snowflake, which facilitates massive dataset storage for companies, revealed that hackers have been attempting to Continue reading The Snowflake Attack Could Become One of the Largest Data Breaches in History

Fake “Crytic-Compilers” Target Python Developers on PyPI

Cybersecurity researchers have discovered a harmful Python package on the Python Package Index (PyPI) repository, designed to deploy an information-stealing malware known as Lumma (also referred to as LummaC2). via GIPHY The malicious package, named crytic-compilers, is a typosquatted version Continue reading Fake “Crytic-Compilers” Target Python Developers on PyPI

Millions of WordPress Sites Exposed: Popular Plugins Leave Backdoor Wide Open 

Cloud security provider Fastly uncovers critical flaws in widely used plugins, exposing millions of WordPress websites to potential compromise. Fastly’s security researchers identified unauthenticated stored Cross-Site Scripting (XSS) vulnerabilities in three popular WordPress plugins: WP Meta SEO, WP Statistics, and Continue reading Millions of WordPress Sites Exposed: Popular Plugins Leave Backdoor Wide Open