Keepnet Labs Logo
Menu
HOME > newsletters > weekly cybersecurity newsletter no 195

WEEKLY CYBERSECURITY NEWSLETTER NO: 195

#WeeklyCybersecurityTip: You are a target to hackers. Don’t ever say “It won’t happen to ME.”

Nov 29, 2021 8:39 am

1- 80K Retail WooCommerce Sites Exposed by Plugin XSS Bug

The plugin “Variation Swatches for WooCommerce,” installed across 80,000 WordPress-powered retail sites, contains a stored cross-site scripting (XSS) security vulnerability that could allow cyberattackers to inject malicious web scripts and take over sites. Variation Swatches is designed to allow re…

Read More

2- Stealthy ‘WIRTE’ Gang Targets Middle Eastern Governments

A threat actor tracked as WIRTE has been assaulting Middle East governments since at least 2019 using “living-off-the-land” techniques and malicious Excel 4.0 macros. On Monday, Kaspersky reported that it observed the group in February using Microsoft Excel droppers, which planted hidden spreadsheet…

Read More

3- Intel Is Maintaining Legacy Technology for Security Research

Interesting: Intel’s issue reflects a wider concern: Legacy technology can introduce cybersecurity weaknesses. Tech makers constantly improve their products to take advantage of speed and power increases, but customers don’t always upgrade at the same pace. This creates a long tail of old products t…

Read More

4- Most Inspiring Women in Cyber 2021: Areej Eliyan, IT Administrator at MOEHE Qatar

The IT Security Guru’s Most Inspiring Women in Cyber Awards aims to shed a light on the remarkable women in our industry. The following is a feature on just one of the many phenomenal women put forward for the 2021 awards. Presented in a Q&A format, the nominee’s answers are written in their own wor…

Read More
Weekly Cybersecurity Newsletter No: 195

SHARE ON

twitter
linkedin
facebook

Download Newsletter

Schedule your 30-minute demo now

You'll learn how to:
tickAutomate behaviour-based security awareness training for employees to identify and report threats: phishing, vishing, smishing, quishing, MFA phishing, callback phishing!
tickAutomate phishing analysis by 187x and remove threats from inboxes 48x faster.
tickUse our AI-driven human-centric platform with Autopilot and Self-driving features to efficiently manage human cyber risks.