Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

548 result(s) for "PHP" — best match first.

What it means for your servers

The security stories that matter, explained by our team — with the concrete steps to take.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3956-1: smarty3 Security Advisory Updates

Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScrip…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Alerts
Debian: DSA-5813-1: symfony Security Advisory Updates

Moritz Rauch discovered that the Symfony PHP framework implemented persisted remember-me cookies incorrectly, which could result in authentication bypass.

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian: DSA-5809-1: symfony Security Advisory Updates

Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to privilege escalation, information disclosure, incorrect validation or…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Alerts
Debian: DSA-5780-1: php8.2 Security Advisory Updates

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in incorrect parsing of multipart/f…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3838-1: composer Security Advisory Updates

It was discovered that there were a number of command-line injection vulnerabilities in Composer, a popular dependency manager for PHP. The 'install', 'status'…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Alerts
Debian LTS: DLA-3833-1: php7.3 Security Advisory Updates

PHP, a widely-used open source general purpose scripting language, is affected by a security problem when parsing certain types of URLs. Due to a code logic er…

Linux PHP

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
CVE-2024-4577: A Swiftly Weaponized Vulnerability for Ransomware Distribution

Security researchers recently issued an update detailing how attackers are exploiting a PHP code execution vulnerability to spread TellYouThePass ransomware . …

PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Alerts
Debian LTS: DLA-3810-1: php7.3 Security Advisory Updates

Security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in information disclosure or incorrect vali…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Alerts
Debian: DSA-5661-1: php8.2 Security Advisory Updates

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in secure cookie bypass, XXE attack…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3777-1: composer security update

Composer, an application-level dependency manager for the PHP programming language was vulnerable. CVE-2023-43655:

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian: DSA-5632-1: composer security update

It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege …

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3756-1: wordpress security update

Two security vulnerabilities have been discovered in Wordpress, a popular content management framework, a PHP File Upload bypass via the plugin installer and a…

Linux WordPress PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories
Debian LTS: DLA-3749-1: phpseclib security update

Security issues were discovered in phpseclib, a PHP library for arbitrary-precision integer arithmetic, which could lead to Denial of Service.

Linux PHP

The Hacker News
The Hacker News Vulnerabilities
WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites

A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations.…

WordPress PHP

The Hacker News
The Hacker News
SystemBC Malware's C2 Server Analysis Exposes Payload Delivery Tricks

Cybersecurity researchers have shed light on the command-and-control (C2) server workings of a known malware family called SystemBC."SystemBC can be purchased …

PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3719-1: phpseclib security update

It was discovered that phpseclib, a PHP library for arbitrary-precision integer arithmetic, was vulnerable to the so-called Terrapin Attack. The SSH transport …

Linux PHP OpenSSH

The Hacker News
The Hacker News Vulnerabilities
WordPress Releases Update 6.4.2 to Address Critical Remote Attack Vulnerability

WordPress has released version 6.4.2 with a patch for a critical security flaw that could be exploited by threat actors by combining it with another bug to exe…

WordPress PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3555-1: php7.3 security update

Security issues were found in PHP, a widely-used open source general purpose scripting language, which could result in information disclosure, denial of servic…

Linux PHP

The Hacker News
The Hacker News Vulnerabilities
Alert: Juniper Firewalls, Openfire, and Apache RocketMQ Under Attack from New Exploits

Recently disclosed security flaws impacting Juniper firewalls, Openfire, and Apache RocketMQ servers have come under active exploitation in the wild, according…

Apache PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories
Mageia 2023-0241: mediawiki security update

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a n…

PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Vulnerabilities
Debian LTS: DLA-3493-1: symfony security update

Multiple security vulnerabilities were found in symfony, a PHP framework for web and console applications and a set of reusable PHP components, which could lea…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Debian LTS: DLA-3458-1: php7.3 security update

Niels Dossche and Tim D'¼sterhus discovered that PHP's implementation of the SOAP HTTP Digest authentication did not check for failures, which may result in a …

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Debian: DSA-5425-1: php8.2 security update

It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…

Linux PHP

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Debian: DSA-5424-1: php7.4 security update

It was discovered that PHP's implementation of SOAP HTTP Digest authentication performed insufficient error validation, which may result in a stack information…

Linux PHP