CISA Unaware of Any Significant Log4j Breaches in U.S.

cisa-unaware-of-any-significant-log4j-breaches-in-us.

CISA Concerned About Risk Posed by Log4Shell to Critical Infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) says it’s currently unaware of any significant breaches related to the recently disclosed Log4j vulnerabilities.

read more

WordPress 5.8.3 Patches Several Injection Vulnerabilities

wordpress-58.3-patches-several-injection-vulnerabilities

WordPress 5.8.3, a security release that became available last week, patches four injection-related vulnerabilities.

Two of the flaws are SQL injections — one affects WP_Meta_Query (discovered by Ben Bidner of the WordPress security team) and one affects WP_Query (discovered by ngocnb and khuyenn of GiaoHangTietKiem JSC).

read more