WordPress and Annotum for Education, Science,Journal Publishing
4.7K views | +0 today
Follow
WordPress and Annotum for Education, Science,Journal Publishing
WordPress and Annotum for Education, Science,Professional Journal Publishing with multiple authors and peer-reviews as also Knol to WP Migration...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

All websites running WordPress urged to update NOW | #CyberSecurity #Updates #Awareness

All websites running WordPress urged to update NOW | #CyberSecurity #Updates #Awareness | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Millions of websites running WordPress are being strongly urged to update to the latest version of the popular content management system as soon as possible, after a serious security vulnerability was uncovered.
No comment yet.
Scooped by Gust MEES
Scoop.it!

Gefaktes Sicherheits-Plugin für WordPress im Umlauf | #CyberSecurity #Blogs #blogging 

Gefaktes Sicherheits-Plugin für WordPress im Umlauf | #CyberSecurity #Blogs #blogging  | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Von wegen Sicherheit: Unter dem Deckmantel eines legitimen WordPress-Plugin richtet X-WP-SPAM-SHIELD-PRO eine Backdoor auf Webseiten ein.

Wer auf seiner WordPress-Webseite das Plugin X-WP-SPAM-SHIELD-PRO installiert hat, sollte dieses schleunigst deinstallieren: Das Fake-Sicherheits-Plugin ist Malware und richtet unter anderem einen Fernzugriff für die Drahtzieher des Zusatzmoduls ein, warnen Sicherheitsforscher von Sucuri.

Die Betrüger missbrauchen dabei den Namen des legitimen Sicherheits-Plugins WP-SpamShield Anti-Spam, welches Spam von WordPress-Seiten fernhalten soll. X-WP-SPAM-SHIELD-PRO ist nicht im offiziellen Plugin-Bereich von WordPress zu finden. Es stammt aus einer von den Sicherheitsforschern nicht näher beschriebenen Quelle. Aus Sicherheitsgründen ist es ratsam, nur Plugins aus der offiziellen Quelle zu installieren.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

Gust MEES's insight:
Von wegen Sicherheit: Unter dem Deckmantel eines legitimen WordPress-Plugin richtet X-WP-SPAM-SHIELD-PRO eine Backdoor auf Webseiten ein.

Wer auf seiner WordPress-Webseite das Plugin X-WP-SPAM-SHIELD-PRO installiert hat, sollte dieses schleunigst deinstallieren: Das Fake-Sicherheits-Plugin ist Malware und richtet unter anderem einen Fernzugriff für die Drahtzieher des Zusatzmoduls ein, warnen Sicherheitsforscher von Sucuri.

Die Betrüger missbrauchen dabei den Namen des legitimen Sicherheits-Plugins WP-SpamShield Anti-Spam, welches Spam von WordPress-Seiten fernhalten soll. X-WP-SPAM-SHIELD-PRO ist nicht im offiziellen Plugin-Bereich von WordPress zu finden. Es stammt aus einer von den Sicherheitsforschern nicht näher beschriebenen Quelle. Aus Sicherheitsgründen ist es ratsam, nur Plugins aus der offiziellen Quelle zu installieren.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Over a million websites could be at risk from critical WordPress gallery plugin flaw | #CyberSecurity

Over a million websites could be at risk from critical WordPress gallery plugin flaw | #CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
NextGEN Gallery is an extraordinarily popular plugin for self-hosted WordPress websites, having been downloaded over 16.5 million times.

The software’s widespread popularity (it claims to have been “the industry’s standard WordPress gallery plugin” since 2007) makes it an seemingly obvious choice for website owners looking to add image galleries to their sites.

Researchers at Sucuri uncovered a severe SQL injection vulnerability in NextGEN Gallery’s code which could be used by a malicious attacker to steal sensitive information such as hashed passwords and WordPress secret keys:

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

Gust MEES's insight:
NextGEN Gallery is an extraordinarily popular plugin for self-hosted WordPress websites, having been downloaded over 16.5 million times.

The software’s widespread popularity (it claims to have been “the industry’s standard WordPress gallery plugin” since 2007) makes it an seemingly obvious choice for website owners looking to add image galleries to their sites.

Researchers at Sucuri uncovered a severe SQL injection vulnerability in NextGEN Gallery’s code which could be used by a malicious attacker to steal sensitive information such as hashed passwords and WordPress secret keys:

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

100,000+ WordPress webpages defaced as recently patched vulnerability is exploited | #CyberSecurity

100,000+ WordPress webpages defaced as recently patched vulnerability is exploited | #CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Keep your WordPress site updated, or risk having hackers modify the content of any post or webpage.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

Gust MEES's insight:
Keep your WordPress site updated, or risk having hackers modify the content of any post or webpage.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

WordPress bloggers 'strongly encouraged' to immediately apply security update | #Updates #CyberSecurity #blogs

WordPress bloggers 'strongly encouraged' to immediately apply security update | #Updates #CyberSecurity #blogs | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
With the huge number of sites running WordPress, and the frequency with which attackers exploit vulnerabilities on the platform to launch malicious attacks, it makes sense for self-hosting bloggers to update their systems as soon as possible.

Security vulnerabilities are frequently uncovered in third-party WordPress plugins, but the above fix addresses bugs in the main WordPress content management system itself. Meaning that just about any site running WordPress could be at risk.

Fortunately, updating is pretty easy. Go to your WordPress admin panel and choose Dashboard > Updates.

Of course, it's always good practice to test a new version of the software on a non-live version of your site first (often known as a staging site) - just in case.

Since WordPress 3.7 was released in October 2013, the software has come with the option of automatic security updates - hopefully ensuring that many site admins won't have to worry so much about whether they have kept their software updated or not.

But, of course, there will always be those who don't have automatic updates enabled and may miss the news.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?tag=Cybersecurity

 

Gust MEES's insight:
With the huge number of sites running WordPress, and the frequency with which attackers exploit vulnerabilities on the platform to launch malicious attacks, it makes sense for self-hosting bloggers to update their systems as soon as possible.

Security vulnerabilities are frequently uncovered in third-party WordPress plugins, but the above fix addresses bugs in the main WordPress content management system itself. Meaning that just about any site running WordPress could be at risk.

Fortunately, updating is pretty easy. Go to your WordPress admin panel and choose Dashboard > Updates.

Of course, it's always good practice to test a new version of the software on a non-live version of your site first (often known as a staging site) - just in case.

Since WordPress 3.7 was released in October 2013, the software has come with the option of automatic security updates - hopefully ensuring that many site admins won't have to worry so much about whether they have kept their software updated or not.

But, of course, there will always be those who don't have automatic updates enabled and may miss the news.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?tag=Cybersecurity

 

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

All WordPress users urged to update after critical flaw found | CyberSecurity

All WordPress users urged to update after critical flaw found | CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
The latest version of the software, a security update, is WordPress 4.2.3.
Gust MEES's insight:

The latest version of the software, a security update, is WordPress 4.2.3.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Hey, maybe ISIS can get you to update your WordPress site's security? | CyberSecurity

Hey, maybe ISIS can get you to update your WordPress site's security? | CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
The FBI has issued a warning that ISIS-supporting hackers are exploiting vulnerabilities on websites running WordPress.
Gust MEES's insight:

The FBI has issued a warning that ISIS-supporting hackers are exploiting vulnerabilities on websites running WordPress.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Four WordPress WPML Plugin Vulnerabilities Impact 400,000 Websites | CyberSecurity | #digcit

Four WordPress WPML Plugin Vulnerabilities Impact 400,000 Websites | CyberSecurity | #digcit | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Multiple vulnerabilities in the WPML plugin that could allow attackers to access databases, delete site content, and gain administrative privileges have put as many as 400,000 websites at risk.

WPML is a popular WordPress plugin used for creating multi-lingual websites, and researchers have uncovered four critical vulnerabilities, the most serious being a SQL injection flaw that can allow unauthenticated access to the website’s database, exposing user details and password hashes.
Gust MEES's insight:

Multiple vulnerabilities in the WPML plugin that could allow attackers to access databases, delete site content, and gain administrative privileges have put as many as 400,000 websites at risk.

WPML is a popular WordPress plugin used for creating multi-lingual websites, and researchers have uncovered four critical vulnerabilities, the most serious being a SQL injection flaw that can allow unauthenticated access to the website’s database, exposing user details and password hashes.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Over 1 million WordPress websites at risk from SQL injection | CyberSecurity

Over 1 million WordPress websites at risk from SQL injection | CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
A critical security flaw in a plugin called WP-Slimstat is to blame.


Over one million websites running the WordPress content management system are potentially at risk of being hijacked due to a critical vulnerability exposed in the WP-Slimstat plugin.

On Tuesday, a security advisory posted by researcher Marc-Alexandre Montpas from security firm Sucuri said the "very high risk" vulnerability found in versions of WP-Slimstat 3.9.5 and lower could lead to cyberattackers being able to break the plugin's "secret" key, perform an SQL injection and take over a target website.


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing


Gust MEES's insight:
A critical security flaw in a plugin called WP-Slimstat is to blame.


Over one million websites running the WordPress content management system are potentially at risk of being hijacked due to a critical vulnerability exposed in the WP-Slimstat plugin.

On Tuesday, a security advisory posted by researcher Marc-Alexandre Montpas from security firm Sucuri said the "very high risk" vulnerability found in versions of WP-Slimstat 3.9.5 and lower could lead to cyberattackers being able to break the plugin's "secret" key, perform an SQL injection and take over a target website.


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing


No comment yet.
Scooped by Gust MEES
Scoop.it!

ALERT! | Major Security Vulnerability in WordPress, Drupal Could Take Down Websites

ALERT! | Major Security Vulnerability in WordPress, Drupal Could Take Down Websites | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
If your website runs on a self-hosted WordPress installation or on Drupal, update your software now.
Gust MEES's insight:

If your website runs on a self-hosted WordPress installation or on Drupal, update your software now.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Serious security hole found in All in One SEO WordPress plugin

Serious security hole found in All in One SEO WordPress plugin | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Do you use the popular All in One SEO Pack plugin on your WordPress website?


===> If so, you need to update the plugin as soon as possible to the latest version!!! <===


Gust MEES's insight:
Do you use the popular All in One SEO Pack plugin on your WordPress website?


===> If so, you need to update the plugin as soon as possible to the latest version!!! <===


No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Sucuri Security: Is your WordPress Site being used to attack others?

Sucuri Security: Is your WordPress Site being used to attack others? | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Web site security monitoring and malware removal


Is my WordPress Site DDOS'ing others?

Lately we are seeing many legitimate and clean WordPress sites being misused on DDOS attacks. We explain in more detail in our blog how it can happen.

.

Example of site being misused: here. If you have any questions, please contact us at labs@sucuri.net or hit us on Twitter - @Sucuri_Security.

.

===> Check out if YOUR WordPress site is secure! <===


Gust MEES's insight:


===> Check out if YOUR WordPress site is secure! <===



Gust MEES's curator insight, March 13, 2014 5:15 PM


===> Check out if YOUR WordPress site is secure! <===


Scooped by Gust MEES
Scoop.it!

WordPress WP-E-Commerce : multiples vulnérabilités

WordPress WP-E-Commerce : multiples vulnérabilités | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Ce bulletin a été rédigé par Vigil@nce : http://vigilance.fr/offre SYNTHÈSE DE LA VULNÉRABILITÉ Un attaquant peut employer plusieurs vulnérabilités de (...)


Gravité : 2/4

Date création : 24/01/2014

DESCRIPTION DE LA VULNÉRABILITÉ

Plusieurs vulnérabilités ont été annoncées dans WordPress WP-E-Commerce.

Un attaquant peut uploader un fichier illicite via save-data.functions.php, afin par exemple de déposer un Cheval de Troie. [grav:2/4]

Un attaquant peut utiliser ajax.php, afin d’exécuter du code. [grav:2/4]

Un attaquant peut utiliser display-sales-logs.php, afin d’exécuter du code. [grav:2/4]

Un attaquant peut utiliser misc.functions.php, afin d’obtenir des informations sensibles. [grav:2/4]

Un attaquant peut provoquer un Cross Site Scripting dans swfupload.swf, afin d’exécuter du code JavaScript dans le contexte du site web. [grav:2/4]

Gust MEES's insight:


Learn more:


http://vigilance.fr/vulnerabilite/WordPress-WP-E-Commerce-multiples-vulnerabilites-14131


No comment yet.
Scooped by Gust MEES
Scoop.it!

'Critical' zero-day bug found in three popular WordPress plugins | #Update asap!!! | #CyberSecurity #Blogs

'Critical' zero-day bug found in three popular WordPress plugins | #Update asap!!! | #CyberSecurity #Blogs | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Outdated versions of three popular WordPress plugins suffer from a "critical" zero-day vulnerability that enables an attacker to take over a website.

The bug is a PHP object injection flaw that affects the following plugins: Appointments (versions prior to 2.2.2), Flickr Gallery (versions prior to 1.5.3), and RegistrationMagic-Custom Registration Forms (versions prior to 3.7.9.3).

Together, those plugins have a combined user base of over 21,000 WordPress customers. All three have already received a fix for the security issue, which is rated "Critical" with a CVSS rating of 9.8.

 

 Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

 

Gust MEES's insight:
Outdated versions of three popular WordPress plugins suffer from a "critical" zero-day vulnerability that enables an attacker to take over a website.

The bug is a PHP object injection flaw that affects the following plugins: Appointments (versions prior to 2.2.2), Flickr Gallery (versions prior to 1.5.3), and RegistrationMagic-Custom Registration Forms (versions prior to 3.7.9.3).

Together, those plugins have a combined user base of over 21,000 WordPress customers. All three have already received a fix for the security issue, which is rated "Critical" with a CVSS rating of 9.8.

 

 Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

WordPress 4.8.2 is out, update your website now! | #Updates #Blogs #blogging #CyberSecurity

WordPress 4.8.2 is out, update your website now! | #Updates #Blogs #blogging #CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
WordPress 4.8.2 is out, featuring nine security fixes website owners will want to apply, well, now.

All told, there have been six updates this year featuring security fixes, including January’s silent patch for a nasty zero day, this being the first since May’s v4.7.5.

The maintenance side of the update features six other software updates but focussing on the bit that bothers Naked Security readers most, security, we see five Cross-Site Scripting (XSS) flaws (a perennially popular attack vector that refuses to die), two path or directory traversal issues, and one covering an open redirect.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

Gust MEES's insight:
WordPress 4.8.2 is out, featuring nine security fixes website owners will want to apply, well, now.

All told, there have been six updates this year featuring security fixes, including January’s silent patch for a nasty zero day, this being the first since May’s v4.7.5.

The maintenance side of the update features six other software updates but focussing on the bit that bothers Naked Security readers most, security, we see five Cross-Site Scripting (XSS) flaws (a perennially popular attack vector that refuses to die), two path or directory traversal issues, and one covering an open redirect.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

Cybercriminals start cashing in on vulnerable WordPress websites | #CyberSecurity #Blogs #Awareness 

Cybercriminals start cashing in on vulnerable WordPress websites | #CyberSecurity #Blogs #Awareness  | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Domains are being compromised through a vulnerability in the WordPress REST API.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

Gust MEES's insight:
Domains are being compromised through a vulnerability in the WordPress REST API.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?&tag=Cybersecurity

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

#Update asap!!! WordPress corrige des vulnérabilités très critiques | #Updates #CyberSecurity #Blogs

#Update asap!!! WordPress corrige des vulnérabilités très critiques | #Updates #CyberSecurity #Blogs | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Attention menaces. WordPress a patché trois vulnérabilités, dont une faille de type XSS (cross-site scripting) et un problème d’injection SQL pouvant déboucher sur la création de vulnérabilités supplémentaires.

La semaine dernière, les développeurs du logiciel de CMS annonçaient dans un bulletin de sécurité que les nouveaux correctifs remédiaient à trois importants problèmes de sécurité, tous affectant WordPress versions 4.7.1 et antérieures.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

 

Gust MEES's insight:
Attention menaces. WordPress a patché trois vulnérabilités, dont une faille de type XSS (cross-site scripting) et un problème d’injection SQL pouvant déboucher sur la création de vulnérabilités supplémentaires.

La semaine dernière, les développeurs du logiciel de CMS annonçaient dans un bulletin de sécurité que les nouveaux correctifs remédiaient à trois importants problèmes de sécurité, tous affectant WordPress versions 4.7.1 et antérieures.

 

Learn more / En savoir plus / Mehr erfahren:

 

http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing

 

No comment yet.
Scooped by Gust MEES
Scoop.it!

ALERT!!! Jetzt Update installieren: WordPress behebt XSS-Lücke | Blogs | Blogging | CyberSecurity | Updates

ALERT!!! Jetzt Update installieren: WordPress behebt XSS-Lücke | Blogs | Blogging | CyberSecurity | Updates | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Über eine Cross-Site-Scripting-Schwachstelle können Angreifer WordPress-Installationen kompromittieren. Betroffen sind alle Versionen bis einschließlich WordPress 4.4.

Mit einem Wartungs-Update beheben die Entwickler des Content-Management-Systems WordPress insgesamt 52 Bugs, die seit erscheinen Version 4.4 gefunden wurden. Admins, die Auto-Updates deaktiviert haben, sollten WordPress 4.4.1 schnellstmöglich manuell installieren, da das Update auch eine Cross-Site-Scripting-Lücke (XSS) behebt, über die Angreifer das CMS kompromittieren können.
Gust MEES's insight:

Über eine Cross-Site-Scripting-Schwachstelle können Angreifer WordPress-Installationen kompromittieren. Betroffen sind alle Versionen bis einschließlich WordPress 4.4.

Mit einem Wartungs-Update beheben die Entwickler des Content-Management-Systems WordPress insgesamt 52 Bugs, die seit erscheinen Version 4.4 gefunden wurden. Admins, die Auto-Updates deaktiviert haben, sollten WordPress 4.4.1 schnellstmöglich manuell installieren, da das Update auch eine Cross-Site-Scripting-Lücke (XSS) behebt, über die Angreifer das CMS kompromittieren können.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Popular WordPress plugins found vulnerable to XSS attacks | UPDATE asap!!!

Popular WordPress plugins found vulnerable to XSS attacks | UPDATE asap!!! | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it

Vulnerable websites can be exploited via XSS to steal user accounts, change settings or phish passwords from unsuspecting users.

In fact, XSS flaws are one of the most commonly encountered security flaws found on websites.


Patching is obviously sensible and should be undertaken at the earliest opportunity, but never forget that additional layers of protection can go beyond patches – and perhaps be proactive in defending your systems from abuse during the time when no official fixes are available.

Gust MEES's insight:

Vulnerable websites can be exploited via XSS to steal user accounts, change settings or phish passwords from unsuspecting users.

In fact, XSS flaws are one of the most commonly encountered security flaws found on websites.


Patching is obviously sensible and should be undertaken at the earliest opportunity, but never forget that additional layers of protection can go beyond patches – and perhaps be proactive in defending your systems from abuse during the time when no official fixes are available.


No comment yet.
Scooped by Gust MEES
Scoop.it!

WordPress plugin used by millions sports critical site-hijacking flaw | CyberSecurity | Blogging

WordPress plugin used by millions sports critical site-hijacking flaw | CyberSecurity | Blogging | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it

Another popular Yoast Wordpress plugin has been found sporting a critical vulnerability that can be exploited by attackers to take over control of the site.

A week ago it was the WordPress SEO plugin, which is actively used on more than a million of WP sites. This time it's the company's Google Analytics plugin, which has apparently been downloaded around 7 million times.

According to the researcher who discovered the issue, Jouko Pynnönen of Finland-based Klikki Oy, the vulnerability "allows an unauthenticated attacker to store arbitrary HTML, including JavaScript, in the WordPress administrator’s Dashboard on the target system. The JavaScript will be triggered when an administrator views the plug-in’s settings panel. No further user interaction is required."


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing


Gust MEES's insight:

Another popular Yoast Wordpress plugin has been found sporting a critical vulnerability that can be exploited by attackers to take over control of the site.

A week ago it was the WordPress SEO plugin, which is actively used on more than a million of WP sites. This time it's the company's Google Analytics plugin, which has apparently been downloaded around 7 million times.

According to the researcher who discovered the issue, Jouko Pynnönen of Finland-based Klikki Oy, the vulnerability "allows an unauthenticated attacker to store arbitrary HTML, including JavaScript, in the WordPress administrator’s Dashboard on the target system. The JavaScript will be triggered when an administrator views the plug-in’s settings panel. No further user interaction is required."


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing


No comment yet.
Scooped by Gust MEES
Scoop.it!

Run WordPress SEO by Yoast on your website? You need to update it | CyberSecurity

Run WordPress SEO by Yoast on your website? You need to update it | CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
A serious vulnerability was found in one of the most popular WordPress plugins, and guess what? It got fixed really quickly. :) All that remains is for you to apply the update on your web server.
Gust MEES's insight:

A serious vulnerability was found in one of the most popular WordPress plugins, and guess what? It got fixed really quickly. :) All that remains is for you to apply the update on your web server.


No comment yet.
Scooped by Gust MEES
Scoop.it!

Thousands of WordPress sites affected by zero-day exploit | CyberSecurity

Thousands of WordPress sites affected by zero-day exploit | CyberSecurity | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Thousands of websites are at risk of being exploited by a previously undisclosed vulnerability in a WordPress plugin, which researchers say could be used to inject malicious code into websites.

The flaw exists in Fancybox, a popular image displaying tool, through which Sucuri researchers say malware or any other script can be added to a vulnerable site.

"We can confirm that this plugin has a serious vulnerability," the researchers wrote. "It's being actively exploited in the wild, leading to many compromised websites," the researchers wrote.
Gust MEES's insight:

Thousands of websites are at risk of being exploited by a previously undisclosed vulnerability in a WordPress plugin, which researchers say could be used to inject malicious code into websites.

The flaw exists in Fancybox, a popular image displaying tool, through which Sucuri researchers say malware or any other script can be added to a vulnerable site.

"We can confirm that this plugin has a serious vulnerability," the researchers wrote. "It's being actively exploited in the wild, leading to many compromised websites," the researchers wrote.


No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Wordpress Sites Seeing Increased Malware, Brute Force Attacks This Week

Wordpress Sites Seeing Increased Malware, Brute Force Attacks This Week | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
A glut of Wordpress sites have fallen victim to both malware infections and a series of brute force attacks that have making the rounds over the past several
Gust MEES's insight:

A glut of Wordpress sites have fallen victim to both malware infections and a series of brute force attacks that have making the rounds over the past several

Gust MEES's curator insight, July 24, 2014 9:25 AM

A glut of Wordpress sites have fallen victim to both malware infections and a series of brute force attacks that have making the rounds over the past several...


Scooped by Gust MEES
Scoop.it!

WordPress Heartbleed Security Update

WordPress Heartbleed Security Update | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
WordPress.com has taken steps to deal with the Heartbleed vulnerability. Here's what you need to know.


Learn more:



Gust MEES's insight:


WordPress.com has taken steps to deal with the Heartbleed vulnerability. Here's what you need to know.


Learn more:




No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Hackers turn 162,000 WordPress sites into DDoS attack tools

Hackers turn 162,000 WordPress sites into DDoS attack tools | WordPress and Annotum for Education, Science,Journal Publishing | Scoop.it
Legitimate sites forced to aid criminals' illicit botnet operations


Hackers have hijacked more than 162,000 legitimate WordPress sites, connecting them to a criminal botnet and forcing them to mount distributed denial-of-service (DDoS) attacks, according to security firm Sucuri.


Sucuri CTO Daniel Cid said the company uncovered the botnet when analysing an attack targeting one of its customers. Cid said Sucuri managed to trace the source of the attack to legitimate WordPress sites.

"The most interesting part is that all the requests were coming from valid and legitimate WordPress sites. Yes, other WordPress sites were sending random requests at a very large scale and bringing the site down," read the blog.


Gust MEES's insight:


Learn more:


http://www.scoop.it/t/wordpress-annotum-for-education-science-journal-publishing/?tag=Botnet


http://www.scoop.it/t/securite-pc-et-internet/?tag=Botnets


http://gustmees.wordpress.com/2012/05/21/visual-it-securitypart2-your-computer-as-a-possible-cyber-weapon/


http://gustmees.wordpress.com/2013/05/13/visual-cyber-security-see-attacks-on-real-time/