Get a Pentest and security assessment of your IT network.

Cyber Security

Unpatched – Critical 0-Day RCE Exploit for vBulletin Forum Disclosed Publicly

Hackers actively exploiting vBulletin zero-day remote code execution vulnerability in forum software. The vulnerability resides in the way an internal widget file of the forum software package accepts configurations via the URL parameters and then parse them on the server without proper safety checks, allowing attackers to inject commands and remotely execute code on the system. Hackers have already started scanning the Internet to target vulnerable vBullets in the wild, sources tell The Hacker News. Vulnerability affects more than 100,000 websites, including Fortune 500 and Alexa Top 1 million companies websites.

Source: https://thehackernews.com/2019/09/vbulletin-zero-day-exploit.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security