Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
••
Sichere ProgrammierungBroadcom erschwert den VMware-Ausstieg(22.09.2026 um 10:36 Uhr)
••••••
Sichere ProgrammierungWhat Did You Deliberately Leave Out of Your MVP?(22.09.2026 um 11:21 Uhr)
•
Sichere ProgrammierungThe Most Useful AI Feature Might Be a Better Question(22.09.2026 um 11:23 Uhr)
•••
Sichere ProgrammierungBroadcom erschwert den VMware-Ausstieg(22.09.2026 um 10:36 Uhr)
••••••
Sichere ProgrammierungWhat Did You Deliberately Leave Out of Your MVP?(22.09.2026 um 11:21 Uhr)
•
Sichere ProgrammierungThe Most Useful AI Feature Might Be a Better Question(22.09.2026 um 11:23 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

Security news weekly round-up - 30th August 2024

Introduction It was a quiet week for articles that could make it into our review for this week's edition. We have just .....checking the number of articles...... four articles to review. These articles are about the…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Introduction



It was a quiet week for articles that could make it into our review for this week's edition. We have just .....checking the number of articles...... four articles to review.



These articles are about the following:




  • Scam

  • Vulnerability

  • Malware



Let's go!









PSA: These ‘Microsoft Support’ ploys may just fool you



The article's title is not clickbait. The threat is real, and without you knowing it, you can fall for it. It all starts with a fake Microsoft advertisement on Google search that takes you to what looks like a real Microsoft website which contains the scammers phone number.



If you think for one second that you can't fall for this. Think again. Strange things can happen if you're under stress while trying to fix your computer. Just saying. Finally, there is no excerpt for this one, go read it and stay safe.






Code Execution Vulnerability Found in WPML Plugin Installed on 1M WordPress Sites



The good news about this bad news is that the developers behind the plugin have fixed it. Therefore, if you're using a version of WPML before 4.6.13, update immediately. What's more, like the previous article, no excerpt can fully capture the essence of the article because I believe if you hear the word Remote Code Execution, you know what it means.



However, if you care about the technical details of the vulnerability, read the full breakdown on the Stealthcopter blog.






Hackers infect ISPs with malware that steals customers’ credentials



What should I say about this? I don't know man. The ISP? The excerpt below (I know, the first one for today 😂), explains what the vulnerability is, when it was patched, and how the threat actors abused it.




CVE-2024-39717, as the zero-day is tracked, is an unsanitized file upload vulnerability that allows for the injection of malicious Java files that run on the Versa systems with elevated privileges.



Versa patched the vulnerability Monday after Lumen privately reported it earlier. All versions of Versa Director prior to 22.1.4 are affected. To fly under the radar, the threat actor waged their attacks through compromised small office and home office routers.







Fake Canva home page leads to browser lock



Yet another scam that starts with a malicious Google search advertisement. Be careful what you believe online, and be careful on what you click. The excerpt below explains how the scammers pulled this off (after the malicious advertisement).




Scammers created a free account on Canva and made a design that looks just like… Canva’s home page. Of all the possible art they could have created, they chose to take a screenshot of Canva’s site and use it as their creation.



This is their “trick”, they want users to think they have landed on the real website and expect them to click on the ‘Start designing’ button.







Credits



Cover photo by Debby Hudson on Unsplash.






That's it for this week, and I'll see you next time.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Security news weekly round-up - 30th August 2024

Thematisch verwandte Begriffe: Security, news, weekly, roundup · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94493 | A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. T…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger • Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick