Joomla 3.8.4 release addresses three XSS and SQL Injection vulnerabilitiesSecurity Affairs·Feb 8, 11:33 UTC · Feb 8, 2018VulnerabilityCVE-2018-637635
Two Critical Vulnerabilities Patched in Joomla 3.6.4. Update it asap!Security Affairs·Oct 26, 06:15 UTC · Oct 26, 2016VulnerabilityCVE-2016-8870CVE-2016-886960
Massive hacking campaign on Joomla sites via recently patched flawsSecurity Affairs·Oct 31, 08:37 UTC · Oct 31, 2016Vulnerability in the wildCVE-2016-8870CVE-2016-886960
Joomla Joomla! Two Critical Flaws Discovered — Update to Protect Your SiteThe Hacker News·Oct 25, 14:50 UTC · Oct 25, 2016VulnerabilityCVE-2016-8870CVE-2016-886960
Critical SQL Injection CVE-2017-8917 vulnerability patched in Joomla, update it now!Security Affairs·May 18, 07:39 UTC · May 18, 2017VulnerabilityCVE-2017-8917CVE-2016-8870CVE-2016-886960
Multiple XSS flaws in Joomla can lead to remote code executionSecurity Affairs·Feb 22, 15:14 UTC · Feb 22, 2024VulnerabilityCVE-2024-21722CVE-2024-21723CVE-2024-21724+3 CVEs47
Latest Joomla 3.7.1 Release Patches Critical SQL Injection AttackThe Hacker News·May 18, 07:41 UTC · May 18, 2017VulnerabilityCVE-2017-891760
Most unpatched Joomla sites compromised in latest wave of attacksHelp Net Security·Oct 31, 00:00 UTC · Oct 31, 2016Vulnerability in the wildCVE-2016-8870CVE-2016-886960
Joomla vulnerability can be exploited to hijack sites, so patch now!Help Net Security·Dec 15, 00:00 UTC · Dec 15, 2016VulnerabilityCVE-2016-983860
Joomla users: Update immediately to kill severe SQLi vulnerabilityHelp Net Security·Oct 15, 09:22 UTC · Oct 15, 2018VulnerabilityCVE-2017-891735
China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt StrikeRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Vulnerability42
Surging CMS attacks keep SQL injections on the radar during the next normalHelp Net Security·Nov 14, 09:12 UTC · Nov 14, 2023Vulnerability42
Shell No! Adversary Web Shell Trends and Mitigations (Part 1)Recorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability42
VMware Alert: Uninstall EAP Now - Critical Flaw Puts Active Directory at RiskThe Hacker News·Feb 22, 02:28 UTC · Feb 22, 2024VulnerabilityCVE-2024-22245CVE-2024-22250CVE-2024-2172660
Pavlov’s Digital House: Russia Focuses Inward for Vulnerability AnalysisRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025VulnerabilityCVE-2018-814860
API Threats Surge to 40,000 Incidents in 1H 2025Infosecurity Magazine·Sep 16, 10:45 UTC · Sep 16, 2025Vulnerability42
China-linked group hacked Tibetan media and university sites to distribute Cobalt Strike payloadThe Record·Nov 13, 03:38 UTC · Nov 13, 2024Vulnerability30
Argus: Open-source information gathering toolkitHelp Net Security·Oct 23, 00:00 UTC · Oct 23, 2024Vulnerability30
CISA Flags 6 Vulnerabilities - Apple, Apache, Adobe, DThe Hacker News·Jan 17, 01:51 UTC · Jan 17, 2024Vulnerability in the wildCVE-2023-27524CVE-2023-38203CVE-2023-29300+3 CVEs160
Friday Squid Blogging: Underwater Sculptures Use Squid Ink for ColoringSchneier on Security·Dec 15, 00:00 UTC · Dec 15, 2023Vulnerability130
New Hacker Group 'GambleForce' Tageting APAC Firms Using SQL Injection AttacksThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023VulnerabilityCVE-2023-2375247
GambleForce Group Targets Websites With SQL InjectionInfosecurity Magazine·Dec 14, 10:00 UTC · Dec 14, 2023Vulnerability30
The Wild West of drive-by cryptocurrency miningHelp Net Security·Nov 21, 07:41 UTC · Nov 21, 2023Vulnerability30
Vulnerability in popular ‘libwebp’ code more widespread than expectedThe Record·Sep 27, 18:08 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-4863CVE-2023-5129CVE-2023-4106460
Watch out! CVE-2023-5129 in libwebp library affects millions appsSecurity Affairs·Sep 27, 13:35 UTC · Sep 27, 2023Vulnerability in the wildCVE-2023-5129CVE-2023-4863CVE-2023-41064+1 CVEs160
Strapi releases update addressing two bugs that lead to data exposureThe Record·Jan 13, 00:00 UTC · Jan 13, 2023VulnerabilityCVE-2022-30617CVE-2022-3061835
CMS-based sites under attack: The latest threats and trendsHelp Net Security·May 3, 00:00 UTC · May 3, 2022Vulnerability42
Drupal-based sites open to attack via double extension files (CVE-2020-13671)Help Net Security·Nov 25, 07:22 UTC · Nov 25, 2020Vulnerability in the wildCVE-2020-1367160
Substantial Rise in Attacks on Orgs’ Web Apps Last YearInfosecurity Magazine·Aug 7, 09:30 UTC · Aug 7, 2020Vulnerability in the wild60
The cybercrime ecosystem: attacking blogsKaspersky Securelist·Nov 21, 10:00 UTC · Nov 21, 2019Vulnerability42
phpMyAdmin Releases Critical Software Update — Patch Your Sites Now!The Hacker News·Dec 11, 15:49 UTC · Dec 11, 2018VulnerabilityCVE-2018-19968CVE-2018-19969CVE-2018-1997060
Prowli Operation - Crooks already compromised over 40,000 servers and IoT DevicesSecurity Affairs·Jun 7, 06:27 UTC · Jun 7, 2018VulnerabilityCVE-2018-7482CVE-2014-262347
Better code won't save developers in the short runHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2018Vulnerability55
Critical Flaw Reported In phpMyAdmin Lets Attackers Damage DatabasesThe Hacker News·Jan 2, 18:35 UTC · Jan 2, 2018Vulnerability55
Qualys brings web application security automation to a new levelHelp Net Security·Feb 13, 00:00 UTC · Feb 13, 2017Vulnerability55
Donald Trump appoints a CyberSecurity Advisor Whose Own Site is Damn VulnerableThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2017Vulnerability30
Critical Updates — RCE Flaws Found in SwiftMailer, PhpMailer and ZendMailThe Hacker News·Jan 5, 07:21 UTC · Jan 5, 2017VulnerabilityCVE-2016-10033CVE-2016-10045CVE-2016-10074+1 CVEs60
Critical RCE vulnerabilities affect SwiftMailer, PhpMailer and ZendMailSecurity Affairs·Jan 3, 13:26 UTC · Jan 3, 2017VulnerabilityCVE-2016-10033CVE-2016-10045CVE-2016-10074+1 CVEs60