The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
#RESEARCH

See the latest resources and content on incident response, business resilience and other topics from the MOXFIVE Technical Advisory team.

RTC security Research, talks and tools. We are researchers in cyber-security, continually educating ourselves and developing knowledge and code. By sharing what we learn, we hope to push RTC security forward.

Read McAfee Labs blogs for the latest threat research, threat intelligence, and thought leadership from the Threat Research team.

Kaspersky's threat research and reports.

The latest research, reports and releases from the minds at Permiso Security.

Browse, search and filter the latest cybersecurity research papers from arXiv.

Thoughts, research, reports, and more from Truffle Security Co.

The Intelligence and research arm of Check Point Technologies provides leading cyber threat intelligence to Check Point customers and the greater intelligence community.

Learn how to protect your ML advantage. Check out HiddenLayer’s recent releases, announcements, and musings on protecting your algorithms.

MDSec was founded on the principles that traditional security assessment describes problems, but Security Education helps fix or avoid them.

This subreddit is for technical professionals to discuss cybersecurity news, research, threats, etc.

Recorded Future’s Insikt Group produces research that creates action to disrupt adversaries. We write on a range of cyber and geopolitical topics, including state-sponsored threat groups; financially-motivated threat actors on the darknet and criminal underground; newly emerging malware and attacker infrastructure; strategic geopolitics; and influence operations.

Explore all of our latest reports to access comprehensive analyses, data-driven insights, and detailed findings. Stay informed with our up-to-date research and understand key trends and developments in predictive security.

RevEng.AI is a deep AI framework for analysing binary computer programs. Read our news and research.

watchTowr Labs is the epicentre of offensive security expertise at watchTowr - injecting offensive security insight, innovation and research into the watchTowr Platform.

Read SafeBreach’s original threat research reports and learn about updates to our Hacker’s Playbook.

Catch up on identity security and PAM trends, cybersecurity best practices, expert research and opinions, and BeyondTrust news and product updates.

Interactive data from scam reports including amount lost, scam types, types of scam and delivery methods.

Cybersecurity News, Awards, eSummits, Research.

Defuse Security. Home of PIE Bin, TRENT, and more...

Talos intelligence and world-class threat research team better protects you and your organization against known and emerging cybersecurity threats.

Discovering the latest attacks and providing defensive measures to keep organizations safe.

The Barracuda blog brings you the latest news, research, and insights you can’t get anywhere else.

Elastic Security Labs empowers security teams across the globe with novel security intelligence research and free to use tools.

The list of research articles compiled by SecurityScorecard.

Understandable online privacy & cybersecurity information to keep you and your data safe. Latest cybersecurity research & trends.

The SecOps Automation Blog. Practical tips & threat analysis from Intezer's Research Team. Product news. Industry insights on the evolution of security operations, automation, and AI.

Our research findings are for everyone’s benefit.

Unit 42 brings together world-renowned threat researchers, incident responders and security consultants to create an intelligence-driven, response-ready organization that's passionate about helping you proactively manage cyber risk.

Keep up with the latest attack trends, research, and cybersecurity industry updates on the Perception Point blog!

The latest cybersecurity trends, best practices, security vulnerabilities, and more.

Cybercrime Magazine by Cybersecurity Ventures provides research and reports on cybercrime costs, cybersecurity market size and spending forecasts, cybersecurity jobs & more.

Get the intelligence you need to detect, prevent & respond to cyber threats. Read the Intel 471 cyber threat intelligence blog.