Turkey cracks down on Meta: interim ban on Instagram and Threads data sharing

0
[ad_1]

Meta is not having a great start of the week. Turkey’s competition watchdog implemented a temporary restriction on Meta to block the exchange of data between Instagram and Threads.

The reason is that there’s an ongoing investigation into Meta’s potential abuse of its dominant position in the market (via Reuters).

This action follows the initiation of a probe in December by the watchdog into Meta, the parent company of Facebook, for potentially breaching competition laws by linking Instagram with its newer platform, Threads.

The watchdog stated that the interim measure will be in effect until a conclusive verdict is reached, since the data obtained and merged through these two apps could “violate competition law and cause irreparable damage” in the market.

On a side note, the Turkish authority fined Meta 4.8 million lira ($148,000) daily as part of a separate investigation over a notification message that the company sends users about the sharing of data.
The notification about data sharing between the company’s Facebook, Instagram, and WhatsApp services did not provide sufficient information and was not transparent enough, it said.

The authority also noted that the manner in which the notification prompts users to consent to data sharing does not adequately mitigate concerns regarding anticompetitive behavior.


[ad_2]
Source link

Acoustic Keyboard Side Channel Attack Let Attackers Steal Data

0
[ad_1]

In recent years, personal data security has surged in importance due to digital device usage. Side-channel attacks exploit system side effects to gather information. 

Electronic emissions are a known vulnerability to such attacks. Acoustic side-channel attacks are particularly threatening. In this attack, threat actors utilize the device’s sound emissions to extract sensitive data.

Cybersecurity researchers, Alireza Taheritajar and Reza Rahaeimehr from Augusta University recently discovered a new acoustic keyboard side-channel attack that lets hackers steal sensitive data.

Acoustic Keyboard Side Channel Attack

Keyboard acoustic side-channel attacks enable threat actors to remotely capture keystroke sounds through microphones and analyze waveforms to determine sensitive information like timing and intensity.

They exploit this data despite background noise challenges, utilizing techniques like statistical analysis, machine learning, signal processing, acoustic triangulation, and Time Difference of Arrival (TDoA).

This made some past studies to limit environmental conditions or ignore irregularities that could interfere with the results. 

However, noise from the surroundings and typing habits of a user are among those factors that are often not considered though they can change how people use keys leading to variations in recognition accuracy.

number of letters on the success rate

This is further complicated by interactions between models and other attributes of emissions that do not have uniform patterns, as well as their dependence on environmental circumstances. 

It also provides an opportunity for keyboard models themselves to spoil up algorithms when altered due to special sound features.

In recent times deep learning approaches bring further complexity to obtaining consistent outcomes. 

In this paper, researchers proposed another approach aimed at eliminating these drawbacks.

It consists of capturing keystroke audio, extracting timing data, training a statistical model for prediction, testing on unknown recordings, and enhancing results with an English dictionary. 

The interface of the data gathering software (Source – Arxiv)

The proposed method analyses typing patterns so as to be able to predict words even in real environments where there is noise and without limiting the keyboard models used.

Researchers’ method assumes identifying the victim, but ours isn’t limited to specific keyboard brands.

They expect victims to work in quiet rooms, allowing noise control through signal processing. 

They gather typing samples, text, and ambient noise to train statistical models.

Analysts assume an oracle can split audio into word files, which is realistic as users often generate distinct sounds by pressing the Enter or Space keys after typing.

A Windows app written in C# by experts to record keystroke sounds under three conditions:- 

  • Users just typing
  • Researchers typing sentences
  • Developers using normal words

Different sentences and words were chosen to represent various styles and trends of English typing.

Researchers conducted an IRB-approved study to collect typing patterns from 20 adult users, ensuring confidentiality and anonymity. 

Datasets included common English words to measure word length’s impact on prediction accuracy.

Visual representation in Figure 5 shows success rates increasing with word length up to six letters, then plateauing.

The researchers are trying to reduce reliance on environmental conditions in their approach, but accurately capturing the keyboard sounds is very important for precise keystroke identification. 

Acoustic detection methods rely on the production of sufficient sound by keyboards in order to overcome challenges with softer keys that may lower the accuracy. 

The technique supposes that users maintain consistent and recognizable typing patterns when constructing datasets. 

In this way, it is possible to deduce whether a certain key was pressed or not based on the variance between different key presses on the same computer.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link

E-commerce & Aviation Industries Targeted

0
[ad_1]
Dark Web Tool Arms Ransomware Gangs: E-commerce & Aviation Industries Targeted

Cybersecurity researchers have published two concerning reports where the first report highlights the surge in cyber attacks against the aviation and aerospace industries – And the second report exposes a dark web tool called TMChecker fueling attacks against E-commerce platforms.

Recent cyber incidents targeting the aerospace and aviation sectors have raised concerns about the industry’s vulnerability to malicious attacks, according to a report by Resecurity. The report highlights the critical need for strong cybersecurity risk assessments to protect airports and aviation infrastructure.

The aerospace sector, including the design, manufacturing, and maintenance of aircraft and spacecraft, has become a prime target for cyberattacks due to its reliance on interconnected digital infrastructures and global supply chains.

The integration of Industrial Internet of Things (IIoT) technologies has further strengthened this threat, making aerospace organizations more vulnerable and susceptible to cyber attacks.

Credit: Resecurity

Ransomware Attacks & The Aviation Industry

Ransomware emerges as a top threat facing the aviation industry, with a 600% increase in occurrences reported by Boeing Chief Security Officer Richard Puckett at the 2023 Aviation Week MRO Americas Conference.

The European Organisation for the Safety of Air Navigation (Eurocontrol) also highlighted ransomware as the sector’s leading attack trend in 2022, accounting for 22% of all malicious incidents. Some of the examples highlighted in the report include the LockBit ransomware gang’s attack on Boeing in November 2023, which the aviation giant later confirmed.

Geopolitical tensions & The Aviation Industry

According to Resecurity’s blog post titled “The Aviation And Aerospace Sectors Face Skyrocketing Cyber Threats,” geopolitical tensions and the designation of aerospace and aviation as critical infrastructure by the U.S. government have fueled cyberattacks targeting the industry.

Threat actors, including hacktivist collectives, are increasingly targeting aviation organizations to advance political agendas or disrupt operations. One such example is the hacktivist group Anonymous Sudan which targeted FlyDubai, an Emirati government-owned airline in Dubai, United Arab Emirates in February 2024 citing the company’s alleged support to the Rapid Support Forces (RSF) in Sudan.

Other recent cyberattacks targeting the aerospace sector include Distributed Denial of Service (DDoS) attacks by groups such as Mysterious Team Bangladesh (MTB) against Saudi Arabian airports and ALTOUFAN TEAM against Gulf Air.

Additional incidents involve ransomware attacks on airlines like Air Albania and Continental Aerospace Technologies, compromising critical data and disrupting operations.

TMChecker – Dark Web Tool Targeting Remote Access and E-Commerce Platforms

In another report published on March 13, 2024, Resecurity detailed a new cybersecurity threat named TMChecker that has surfaced on the Dark Web, posing a notable risk to remote-access services and popular e-commerce applications.

Developed by an actor known as “M762” on the Russian language XSS cybercrime forum, TMChecker is a sophisticated tool that combines corporate access login (log) checking capabilities with a brute-force attack kit. Available for a monthly subscription fee of $200, TMChecker has garnered attention for its ability to target a wide range of VPN gateways, email servers, and e-commerce platforms.

Credit: Resecurity

TMChecker stands out from similar tools like ParanoidChecker due to its focus on corporate remote access gateways, which are often primary targets for ransomware attacks and other malicious activities. The tool supports 17 solutions, including Cisco VPN, Citrix VPN, Office 365, WordPress, Magento, and cPanel, among others, making it a versatile and powerful weapon.

Cybercriminals exploit TMChecker to identify compromised data containing valid credentials for corporate VPN and email accounts. In one observed incident, threat actors used TMChecker to target the email server of a government organization in Ecuador, demonstrating the tool’s real-world impact.

M762 operates a Telegram channel with over 3,270 subscribers, potentially indicating a sizable user base for TMChecker. The addition of such tools aligns with a concerning trend highlighted in recent Microsoft research, which noted a significant increase in human-operated ransomware attacks.

These attacks often involve the abuse of remote monitoring and management tools, leaving behind less evidence compared to automated attacks delivered through malicious documents.

As TMChecker and similar tools lower the barriers to obtaining remote access credentials, the risk of destructive ransomware attacks and other malicious campaigns amplifies. This threat is particularly acute in the context of mergers and acquisitions, where cybercriminals target vulnerable organizations to exploit for financial gain.

  1. Cl0p ransomware gang hits Aviation giant Bombardier
  2. Hackers Uncover Airbus EFB App Flaws, Risking Aircraft Data
  3. Israeli: Hackers Targeted EL AL Flights in Mid-Air Hijack Attempt
  4. Military Satellite Access Sold on Russian Hacker Forum for $15,000
  5. Hackers posing as LinkedIn recruiters to scam military, aerospace firms

[ad_2]
Source link

Price tag of Samsung’s budget foldable seemingly revealed

0
[ad_1]

Samsung is allegedly planning to launch a budget foldable later this year, and its price tag has seemingly been revealed. The device in question is the so-called Galaxy Z Fold 6 FE, which is expected to launch alongside the Galaxy Z Fold 6 in July.

The price tag of Samsung’s upcoming budget foldable has seemingly been revealed

Having said that, a report from Sisa Journal, a Korean publication, claims that the company’s smartphone will cost $800. That’s at least the price tag that Samsung is targeting.

It is also noted that the device will have inferior specifications than the flagship model. To be more specific, it will have an inferior SoC, display, battery, and some other components. The camera specs will be similar to the flagship model, it is noted.

Just to be perfectly clear, the Galaxy Z Fold 6 FE name has not been confirmed, not at all. Samsung’s budget book-style foldable was mentioned a number of times in the last couple of weeks, though.

The ‘Ultra’ model was also mentioned, but that’s not happening, it seems

First, we’ve heard about the Galaxy Z Fold 6 Ultra, but that phone will not be launching after all, it seems. The Galaxy Z Fold 6 and Galaxy Z Fold 6 FE are expected, in addition to the Galaxy Z Flip 6.

A budget clamshell model was not mentioned, this budget foldable is expected to be a book-style foldable. It will be interesting to see what corners will Samsung have to cut in order to reach such a price tag.

An $800 price tag for a book-style foldable would be a true feat for Samsung. That’s basically half the price of the Galaxy Z Fold 5 (at launch). Well, it’s even less than half, as the Galaxy Z Fold 5 was priced at $1,799 at launch.

That price tag even seems a bit unrealistic to us, unless the source was referring to a clamshell foldable, which is probably not the case. It remains to be seen.


[ad_2]
Source link

Former telecom manager pleaded guilty to running SIM swapping scheme

0
[ad_1]

A former telecommunications company manager in New Jersey confessed to involvement in a SIM-swapping scheme. This scheme granted hackers access to sensitive customer data, including emails and social media accounts.

Hackers employ a variety of tactics to breach a victim’s device, one of which is SIM swapping. In simple terms, SIM swapping is a process where an individual, often within the telecommunications company, replaces the targeted phone number with another physical SIM card or eSIM chip under the control of the malicious actor.

The former telecom manager enabled hackers to access the victim’s device through SIM swapping

Hackers might also target customer support agents to perform unauthorized SIM swapping. After a SIM swapping, hackers can read the victim’s SMS to access the one-time passwords sent by two-factor authentication systems.

In this case, Jonathan Katz, aka “Luna,” was the manager of a telecommunications company in Burlington County, New Jersey, who had unauthorized access to a protected computer. He allegedly could access several customers’ accounts via his managerial credentials between May 10 and 20, 2021.

So far, five of Katz’s victims have been detected in Wyoming, New Jersey, California, and Tennessee. He reportedly received $1,000 in Bitcoin per SIM swap and made around $5,000. The hackers could access the victims’ cryptocurrency accounts after SIM swapping, and Katz could have profited from that, too.

“In May 2021, Katz was employed as a manager at a telecommunications store and accessed several customer accounts by using managerial credentials.” the U.S. Department of Justice added. “Katz swapped the SIM numbers associated with the customers’ phone numbers into mobile devices controlled by another individual, enabling this other individual to control the customers’ phones and access the customers’ electronic accounts – including email, social media, and cryptocurrency accounts.”

According to the court order, Katz is sentenced to five years in jail. He should also pay a fine of up to $250,000 or twice the financial gain or loss from the crime.


[ad_2]
Source link

YouTube Music makes finding songs easier with a built-in song recognition feature

0
[ad_1]

YouTube has recently claimed the top spot as the leading streaming service in America. But that is not all, as YouTube Music and YouTube Premium surpassed 100 million subscribers worldwide not long ago. Despite its growing user base, YouTube Music faces tough competition from established platforms like Apple Music and Spotify. However, with each new feature, it aims to carve out a larger share of the market. According to 9to5Google, a new feature enabling song recognition is currently being rolled out to YouTube Music. To use it, you need to first tap the search icon in the top-right corner. Additionally, there is a dedicated button bearing the same icon design as the song search feature on YouTube, positioned next to the voice search option for quicker access.

On YouTube’s main app, the song search feature is available for a while now on Android. To use it, just start a search and tap the “Song” tab instead of “Voice.” Similar to “Hum to Search” in Google Search, you can play, sing, or hum the song you’re looking for. YouTube uses AI to match the sound to the original recording. 


The good news is, unlike YouTube, some YouTube Music users on iOS already have this capability, too, meaning it won’t be exclusive to Android.While both YouTube and YouTube Music come from Google, they have different functions. YouTube is a platform where you can find all sorts of videos, including music videos, movies, tutorials, vlogs, etc. Meanwhile, YouTube Music is solely for streaming music and podcasts.

With that said, it’s logical for the YouTube Music app to include this feature, especially if it aims to compete with others on the market. While Apple Music or Spotify, for instance, don’t offer a built-in feature to recognize songs by humming or listening to them, they both integrate with Shazam.

After all, since Apple owns the popular song identification app, it would be odd not to integrate it with its music streaming service. Once Shazam identifies a song, it offers the option to listen to it on Apple Music. This integration works similarly with Spotify as well.


[ad_2]
Source link

New GhostRace Vulnerability In CPUs May Leak Data

0
[ad_1]

Another security vulnerability has been found in the modern CPUs supporting speculative execution. Identified as “GhostRace”, the vulnerability is a Spectre variant that combines with race condition, exposing data to an adversary.

GhostRace Vulnerability Impacts Most Modern Processors

Researchers from the VUSec group at VU Amsterdam and the Systems Security Research Group at IBM Research Europe have disclosed the details about the newly discovered GhostRace vulnerability threatening most contemporary processors.

Specifically, they identified a speculative execution vulnerability (CVE-2024-2193) – a Spectre variant – exploiting which allows an unauthenticated attacker to access sensitive data.

The researchers demonstrated how the existing synchronization primitives, which operating system apply to prevent race conditions, can be bypassed on speculatively executed code paths, “turning all architecturally race-free critical regions into Speculative Race Conditions (SRCs).”

Describing the SRCs, the researchers stated,

While the effects of SRCs are not visible at the architectural level (e.g., no crashes or deadlocks), due to the transient nature of speculative execution, a Spectre attacker can still observe their microarchitectural effects via side channels. As result, any SRC breaking security invariants can ultimately lead to Spectre gadgets disclosing victim data to the attacker.

For this, they focused on Speculative Concurrent Use-After-Free (SCUAF) information disclosure attacks, exploiting the flaw against over 1200 Linux devices, leaking arbitrary kernel memory at a rate of 12 KB/s.

Regarding the affected software, the researchers explain that “any operating system, hypervisor, synchronization primitives through conditional branches without any serializing instruction on that path and running on any microarchitecture (e.g., x86, ARM, RISC-V, etc.)” is vulnerable to SRCs. Whereas, for the vulnerable hardware, the researchers mention all existing microarchitectures that are vulnerable to Spectre v1, as susceptible to GhostRace.

Users Urged To Patch Their Systems Soon

To address this vulnerability, the researchers propose a generic SRC mitigation to serialize all synchronization primitives. It requires minimal kernel changes and has least performance impact.

Following this discovery, the researchers responsibly disclosed the matter to all hardware vendors (Intel, AMD, ARM, and IBM) and the Linux kernel developers. These vendors further intimated other software vendors to address the matter, while AMD assured that the existing Spectre v1 mitigations apply to GhostRace as well. However, Linux kernel developers haven’t adequately addressed the matter yet.

The researchers have elaborated on their findings in a research paper scheduled for publication at the 33rd USENIX Security Symposium 2024. In addition, they have shared the PoC, the gadget scanner, and other details on a dedicated web page.

Besides, a CERT Coordination Center (CERT/CC) advisory also highlights this vulnerability as a recent security threat targeting the processors. CERT also advised users to update their systems with recent software updates from the respective vendors to receive the patches for this flaw.

Before GhostRace, the same researchers also disclosed the SLAM attack affecting most CPUs, which the vendors patched accordingly following the vulnerability disclosure.

Let us know your thoughts in the comments.


[ad_2]
Source link

NIST NVD Halt Leaves Thousands of Vulnerabilities Untagged

0
[ad_1]
NIST NVD Disruption Leaves Thousands of Vulnerabilities Untagged

Alert! Missing NVD Data Leaves Businesses Vulnerable. Patching Delays Due to Disruption. Security Experts Urge Action.

A disruption at the National Institute of Standards and Technology (NIST) is causing problems for organizations that rely on its National Vulnerability Database (NVD). The NVD is a central repository for information about software vulnerabilities, serving as a critical resource for organizations to identify and address security weaknesses in their systems. 

Security policies mandate governments and commercial organizations to address vulnerabilities based on NVD-provided severity levels within specific days, making it the world’s most significant vulnerability database.

Therefore, it is concerning that NIST has stopped enriching software vulnerabilities in NVD since February 12, 2024. This significant drop in enrichment was first discovered by software security provider Anchore’s VP of Security, Josh Bressers, and subsequently noted by Cisco Threat Detection & Response’s principal engineer, Jerry Gamblin, Gamblin and NetRise.

The NVD announced on February 15th that it is working to establish a consortium to address challenges in the NVD program and develop “improved tools and methods.” This may cause temporary delays in analysis efforts, the NVD explained. However, security analysts opine that the NVD is lagging in fully reporting CVEs.

“NIST is currently working to establish a consortium to address challenges in the NVD program and develop improved tools and methods. You will temporarily see delays in analysis efforts during this transition. We apologize for the inconvenience and ask for your patience as we work to improve the NVD program.”

Hackread.com captured a screenshot from the website, which has been displayed since February 14, 2024.

Screenshot: Hackread.com

As pointed out by a report referring to NetRise CEO Tom Pace, reported that only 200 out of 2700 Common Vulnerabilities and Exposures (CVEs) have been enriched. This means over 2500 vulnerabilities added to the database have been uploaded without crucial metadata information.

These include the description of the vulnerability and software ‘weakness’ potentially leading to an exploit (called Common Weakness and Exposure/CWE), the names of affected software products, the vulnerability’s criticality/CVSS score, and patching status. Bressers shared an updated graph showing few CVEs have been enriched in the past 30 days.

The issue is attributed to a decrease in CVEs enriched with crucial metadata, such as Common Product Enumerators (CPEs) and criticality scores (CVSS). The NVD has left thousands of CVEs untagged since mid-February, leaving around 40% of this year’s CVEs without vital information. This is concerning as CPE is the main way to match a CVE to a component and relies on many home-grown vulnerability solutions.

For your information, MITRE developed the CVE framework to identify known security flaws. CVE IDs are reported by CVE Numbering Authorities, which include 350 tech companies, security vendors, and researchers.

CVEs are tagged with other cybersecurity acronyms like Common Weakness Enumerators (CWEs), Common Vulnerability Scoring System (CVSS), and Common Platform Enumerator (CPE). CWEs describe coding flaws, CVSS scores describe CVE impact severity, and CPEs identify systems in danger.

This disruption poses a significant challenge to organizations that depend on the NVD for vulnerability management. Without access to this comprehensive data, organizations cannot efficiently identify vulnerable systems within their networks. This can lead to delayed patching or remediation efforts, potentially exposing these systems to exploitation by malicious actors.

The cybersecurity researchers are urging NIST to prioritize resolving this interruption and resume providing complete vulnerability data within the NVD. Transparency regarding the cause of this issue is also essential to ensure continued trust and collaboration within the cybersecurity community.

  1. Vulnerability Risk Management for External Assets
  2. ZombieBoy crypto malware exploits CVEs to evade detection
  3. NIST’s Cybersecurity Framework 2.0: Guide for All Organizations
  4. Flashpoint Uncovers 100K+ Hidden Vulnerabilities, Including 0-Days
  5. Ethical Hackers Reported 835 Vulnerabilities, Earned $450K in 2023

[ad_2]
Source link

Meta to shut down CrowdTangle before the US Presidential election

0
[ad_1]

The content discovery and social monitoring platform CrowdTangle will be shut down on August 14, a few weeks before the US Presidential election. CrowdTangle is a subset of Meta, which was bought by the tech giant in 2016.

CrowdTangle has gone through many ups and downs since Meta acquired it. In 2021, Meta discharged the team responsible for running the platform, and in 2022, the platform stopped registering new users. Despite being widely used by academics, journalists, and fact-checkers, CrowdTangle will be sent to Meta Graveyard on August 14.

As the Wall Street Journal reports, Meta Content Library will replace CrowdTangle. However, the new platform will only be available to academics and nonprofit researchers. This news is particularly disheartening for independent fact-checkers and for-profit news organizations. Because they have relied on CrowdTangle for their work and now face significant challenges in their operations.

Meta kills CrowdTangle on August 14, introducing Content Library as a replacement

Meta Content Library was initially launched to comply with the EU’s Digital Markets Act. Meanwhile, the company claims its new platform has some new features. Including data on public comments and the ability to search content based on views.

While the platform is still in its beta phase, early adopters have expressed their disappointment. They noted that it lags behind CrowdTangle and lacks essential features such as the ability to download data from public posts. The shutdown of CrowdTangle is a significant setback for organizations and individuals who relied on its insightful data for their research. And the loss of such a valuable platform could potentially impact transparency and free data access.

Meta’s decision to shut down CrowdTangle 12 weeks before the US Presidential election has sparked controversy. In a time when the flow of rumors and fake news reaches its peak, the absence of a platform like CrowdTangle, which could greatly assist journalists and fact-checkers, is a matter of significant concern.

CrowdTangle’s former co-founder and CEO Brandon Silverman blamed Meta for shutting down the platform just before the US election, adding that the decision was “incredibly irresponsible.” Silverman also said Meta Content Library has some huge gaps and is not close to CrowdTangle yet.


[ad_2]
Source link

Discontinued WordPress Plugin Flaw Exposes Websites to Attacks

0
[ad_1]

A critical vulnerability was discovered in two plugins developed by miniOrange.

The affected plugins, miniOrange’s Malware Scanner and Web Application Firewall, contained a severe privilege escalation flaw that could allow unauthenticated attackers to gain administrative access to WordPress sites.

This discovery underscores website administrators’ ongoing risks and challenges in securing their digital assets against sophisticated cyber threats.

The core of the issue lies in a privilege escalation vulnerability identified under the CVE ID CVE-2024-2172. It has a CVSS score of 9.8, indicating a critical level of severity.

Document

Free Webinar : Mitigating Vulnerability & 0-day Threats

Alert Fatigue that helps no one as security teams need to triage 100s of vulnerabilities.:

  • The problem of vulnerability fatigue today
  • Difference between CVSS-specific vulnerability vs risk-based vulnerability
  • Evaluating vulnerabilities based on the business impact/risk
  • Automation to reduce alert fatigue and enhance security posture significantly

AcuRisQ, that helps you to quantify risk accurately:

This flaw was present in versions up to and including 4.7.2 of the Malware Scanner plugin and 2.1.1 of the Web Application Firewall plugin.

The vulnerability allowed unauthenticated individuals to escalate their privileges to that of an administrator by updating the user password through a missing capability check in the mo_wpns_init() function.

Discovery and Response

The vulnerability was discovered by a researcher named Stiofan, who reported it through the Wordfence Bug Bounty Program during their second Bug Bounty Extravaganza on March 1, 2024.

Wordfence, a leading provider of WordPress security solutions, confirmed the flaw and identified that it also affected the miniOrange’s Web Application Firewall plugin.

In recognition of the discovery, Stiofan was awarded a bounty of $1,250.00.

Wordfence acted swiftly to mitigate the risk posed by this vulnerability.

On March 4, 2024, Premium, Care, and Response users of Wordfence received a firewall rule to protect against exploits targeting this flaw.

Users of the accessible version of Wordfence were scheduled to receive the same protection on April 3, 2024.

Upon notification of the vulnerability, miniOrange responded by permanently closing the affected plugins on March 7, 2024, leaving no patch or update available for users.

This drastic measure highlights the severity of the vulnerability and the potential risks to WordPress sites if left unaddressed.

This incident is a stark reminder of the importance of maintaining up-to-date security measures for WordPress sites.

Website administrators are urged to delete the affected miniOrange plugins from their sites immediately and seek alternative solutions to ensure their digital assets remain secure.

Collaborative Efforts in Cybersecurity

The discovery and resolution of this vulnerability demonstrate the critical role of bug bounty programs and collaborative efforts between security researchers and plugin developers in identifying and mitigating security risks.

The Wordfence Bug Bounty Program, in particular, has proven invaluable in securing the WordPress ecosystem by encouraging researchers to report vulnerabilities responsibly.

The discontinuation of miniOrange’s Malware Scanner and Web Application Firewall plugins after discovering a critical privilege escalation vulnerability is a cautionary tale for the WordPress community.

It underscores the need for continuous vigilance, timely updates, and collaborative security efforts to protect against the ever-evolving landscape of cyber threats.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.


[ad_2]
Source link