Think Like A Hacker With Wordfence

Episode 94: Hosting Provider Exposed 63 Million Customer Records

Informações:

Synopsis

A hosting provider exposed over 63 million customer records via an open elastic search database containing verbose logs with plain-text username/password credentials for numerous WordPress, Magento and other sites. We also talk about the security updates in WordPress 5.5.2/5.5.3 and the accidental 5.5.3-alpha autoupdate. We talk about object injection vulnerabilities like the one discovered in the Welcart e-Commerce plugin and how POP chain attacks work. And Google's Project Zero finds a high-severity vulnerability in GitHub Actions not fixed within the 90-day disclosure grace period.

Join Now

Join Now

  • Unlimited access to all content on the platform.
  • More than 30 thousand titles, including audiobooks, ebooks, podcasts, series and documentaries.
  • Narration of audiobooks by professionals, including actors, announcers and even the authors themselves.
Try it Now Firm without compromise. Cancel whenever you want.

Share