Widespread Security Threat: Popular WordPress Event Management Plugin Exploited on 150,000+ Websites

During a security event on May 20th, 2024, researchers discovered a serious flaw in the Modern Events Calendar, a popular WordPress plugin used by over 150,000 websites. This vulnerability allows even basic users, like subscribers, to upload any type of file to affected sites. This could lead to hackers running malicious code on these websites remotely.

Microsoft’s July 2024 Patch Tuesday Addresses 142 Vulnerabilities, Including 4 Zero-Day Issues

Microsoft's July 2024 Patch Tuesday, dedicated to addressing security updates for 142 vulnerabilities. Among these are two zero-day vulnerabilities that have been actively exploited and two others that have been publicly disclosed. This month's updates focus on fixing five critical vulnerabilities, all of which involve remote code execution flaws.