hacking

Unpatched WordPress flaw could allow hackers to reset Admin password

The vulnerability (CVE-2017-8295) becomes even more dangerous after knowing that it affects all versions of WordPress — including the latest 4.7.4 version.

The WordPress flaw was discovered by Polish security researcher Dawid Golunski of Legal Hackers last year in July and reported it to the WordPress security team, who decided to ignore this issue, leaving millions of websites vulnerable.

Emmanuel Macron's presidential campaign hacked

Campaign officials said the perpetrators of the hack -- revealed just two days before the election -- had mixed fake documents with authentic ones "in order to create confusion and misinformation."

About 14.5 gigabytes of emails, personal and business documents were posted, a CNN look at the data shows. Links to the 70,000-plus files were posted on pastebin, a text-sharing site, just before 2 p.m. ET Friday.

WikiLeaks claims to reveal how CIA hacks TVs and phones all over the world

To hide its operations, the CIA routinely adopted hacking techniques that enabled them to appear as if they were hackers in Russia, WikiLeaks said.

WikiLeaks also claimed that nearly all of the CIA's arsenal of privacy-crushing cyberweapons have been stolen, and the tools are potentially in the hands of criminals and foreign spies.

WikiLeaks claimed the stolen tools ended up in the hands of "former U.S. government hackers and contractors... one of whom" leaked documents to WikiLeaks.

Google Increases bug bounty payouts by 50% and Microsoft just doubles it!

Both tech giants Google and Microsoft have raised the value of the payouts they offer security researchers, white hat hackers and bug hunters who find high severity flaws in their products.

While Microsoft has just doubled its top reward from $15,000 to $30,000, Google has raised its high reward from $20,000 to $31,337, which is a 50 percent rise plus a bonus $1,337 or 'leet' award.

Stuffed toys leak millions of voice recordings from kids and parents

A security vulnerability allowed anyone to view personal information, photos and recordings of children's voices from CloudPets toys. And at one point, some people tried to hold all of that information for ransom.

According to a report compiled by security researcher Troy Hunt, over 820,000 user accounts were exposed. That includes 2.2 million voice recordings.

Yahoo hacked once again!

If yes, then you need to think once again, as the company is warning its users of another hack.

Last year, Yahoo admitted two of the largest data breaches on record. One of which that took place in 2013 disclosed personal details associated with more than 1 Billion Yahoo user accounts.

Well, it's happened yet again.

Donald Trump’s website just got hacked

The hacked server, secure2.donaldjtrump.com, which isn’t directly linked to the campaign’s home page, is behind CloudFlare’s content management and security system, Ars Technica reports.

The certificate of the server is legitimate and it looks like a real Trump campaign server. However, the image displayed is linked to some other website. The picture shows the following text:

Wordpress blogs defaced in hack attacks

One estimate suggests more than 1.5 million pages on blogs have been defaced.

The security firm that found the vulnerability said some hackers were now trying to use it to take over sites rather than just spoil pages.

WordPress urged site owners to update software to avoid falling victim.

 

Feeding frenzy

The vulnerability is found in an add-on for the WordPress blogging software that was introduced in versions released at the end of 2016.

Security firms 'overstate hackers' abilities to boost sales'

Dr Ian Levy, technical director of the UK's National Cyber Security Centre, made the accusation in a speech.

He said the firms played up hackers' abilities to help them sell security hardware and services.

Overplaying hackers' skills let the firms claim only they could defeat attackers, a practice he likened to "witchcraft".

In a keynote speech at the Usenix Enigma security conference, Dr Levy said it was dangerous to listen only to firms that made a living from cybersecurity.

MPs question UK's cyber attack defences

The Commons Public Accounts Committee said ministers had taken too long to consolidate the "alphabet soup" of agencies tasked with stopping attacks.

Cyber attacks are ranked among the top four risks to UK national security.

The government said it had acted with "pace and ambition" on the issue.

In November, Chancellor Philip Hammond said that hostile "foreign actors" were developing techniques that threatened the country's electrical grid and airports.

 

'Nato targeted'