Old WordPress Plugin Being Exploited in RCE Attacks

Haythem Elmir

Old instances of the popular WordPress Duplicator Plugin are leaving sites open to remote code execution attacks. Researchers are warning that attackers are abusing a vulnerability in WordPress site admins’ outdated versions of a migration plugin called Duplicator – allowing them to execute remote code. Made by Snap Creek Software, all Duplicator plugins […]

New Brrr Dharma Ransomware Variant Released

Haythem Elmir

A new variant of the Dharma Ransomware was released this week that appends the .brrr extension to encrypted files. This variant was first discovered by Jakub Kroustek who tweeted a link to the sample on VirusTotal.     Below I have outlined how this ransomware infects a computer, what happens when your files […]

Google Android team found high severity flaw in Honeywell Android-based handheld computers

Haythem Elmir

Experts at the Google Android team have discovered high severity privilege escalation vulnerability in some of Honeywell Android-based handheld computers. Security experts from the Google Android team have discovered a high severity privilege escalation vulnerability in some of Honeywell Android-based handheld computers that could be exploited by an attacker to gain elevated privileges. According […]

MageCart Attackers Compromise Cloud Service Firm Feedify

Haythem Elmir

Hundreds of e-commerce Sites Impacted by MageCart Compromise of Cloud Service Provider Payment card data from customers of hundreds of e-commerce websites may have been stolen after the MageCart threat actors managed to compromise customer engagement service Feedify.  Feedify, which claims to have over 4,000 customers, provides customers with various […]