Connect with us

Tech

Beware of These Dangerous WordPress Plugins Infecting Pakistani Websites

Published

on



The Pakistan Telecommunication Authority (PTA) has issued a cybersecurity advisory warning website administrators and developers about multiple vulnerabilities detected in several popular WordPress plugins, posing serious security risks to websites, including those in Pakistan.

According to the advisory, multiple Cross-Site Request Forgery (CSRF) vulnerabilities have been identified in plugins, including MetricThemes Munk Sites, FancyWP Starter Templates, OneStore Sites, WP Keyword Monitor, URL-Preview-Box, Vignette Ads, Show Notice or Message on Admin Area, WP Social Stream, and WP Admin Custom Page. These flaws could allow attackers to perform unauthorized actions on behalf of authenticated users without their consent.

PTA noted that, in some cases, the CSRF vulnerabilities could also lead to Stored Cross-Site Scripting (XSS) attacks, which can further compromise website integrity, steal user data, or inject malicious scripts. The severity of the identified threat has been classified as high, with both CSRF and XSS vectors posing significant exploitation potential if not mitigated promptly.

The advisory urged WordPress users and developers to immediately update the affected plugins to their latest available versions and follow official WordPress security guidelines. It further recommended restricting administrative privileges, enforcing the principle of least privilege, and using trusted security plugins to detect and prevent CSRF and XSS attacks.

PTA also emphasized the importance of user awareness and developer responsibility, advising that CSRF tokens (nonces) be properly implemented and employees be trained in safe computing practices, including recognizing phishing attempts and maintaining secure browsing habits.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Is The Mystery iPhone Update Nearly Here?

Published

on


More than a week ago, the news was clear: the next iPhone update (the content of which remains a mystery) would be iOS 26.0.2 and would land in the week beginning Oct. 20. But it’s nowhere to be seen. What’s happening, you might ask.

It’s not that there were no Apple software updates last week. Anyone who bought the new iPad Pro, which went on sale on Wednesday, Oct. 22 alongside the latest MacBook Pro and Apple Vision Pro, had to update to a new version of iPadOS. But that was iPadOS 26.0.1 and was a new build for the latest model only.

ForbesApple iPhone 16 Pro Prices Slashed Further In New Sale

The iOS 26.0.2 update (and presumably iPadOS 26.0.2 if needed) could have arrived on Thursday, Oct. 23 or Friday, Oct. 24 — several reports thought that was likely.

Since it didn’t, we’re now in different territory. The next big update, until the rumor of iOS 26.0.2 had reared its head, was thought to be iOS 26.1. That’s so far into beta that it’s thought the release candidate will be available on Monday, Oct. 27 or Tuesday, Oct 28, with the general release expected the week after.

There are two options, it seems. Either Apple will kill off iOS 26.0.2 before it sees the light of day and instead go straight to iOS 26.1 on or around Monday, Nov. 3, or iOS 26.0.2 will appear first.

Which really only leaves Monday, Oct. 27 or Tuesday, Oct. 28 as likely days for release.

It’s not known exactly what will be in iOS 26.0.2, though it’s thought to address bugs and flaws, not launch new features which will be part of iOS 26.1.

So the fate of iOS 26.0.2 may rest on how urgent those fixes are and which handsets they affect.

My guess is that we will almost certainly see iOS 26.0.2 on Tuesday, Oct. 28, a day after the release candidate for iOS 26.1. I’d further guess that the fixes will mostly affect the iPhone 17 series or iPhone Air rather than all models.

If there’s no sign of it then, it looks like iOS 26.1 will be the next update, likely on Monday, Nov. 3. Look at it this way, there will probably be a new iPhone update in the next eight days at most.

I’ll update this post as soon as there’s more news, so please check back.

ForbesApple iPhone 18 Could See Major Change To Free Satellite Features, Report Says



Source link

Continue Reading

Tech

X Issues November 10 ‘Account Will Be Locked’ Twitter Security Warning

Published

on


Given the continuing popularity of Elon Musk’s X social network, and the swathing staffing cuts made when the world’s richest man bought what used to be (and still is in my mind) Twitter, it doesn’t make the cybersecurity headlines as much as you might have thought. With PayPal users currently warned of ongoing attacks, ditto WordPress website owners, and even LastPass password manager customers, all being in the threat actor crosshairs, this is a good thing. However, X users have now been warned that unless they make a change to a legacy Twitter security setting, they will be locked out of their accounts from November 10. Here’s what you need to know.

ForbesAct Now — Microsoft Issues Emergency Windows Update As Attacks Begin

The X Safety Team Issues Clarification After Warning Of Twitter Account Lockouts

Whatever you call it, X or Twitter, the social network isn’t immune to security threats. This year alone, I have reported on outages caused by a claimed DDoS attack and a warning for 650 million X users not to change their passwords. Sometimes, though, the perceived security threat comes from inside the building. Such was the case after the X safety team tweeted on October 24: “After November 10, if you haven’t re-enrolled a security key, your account will be locked until you: re-enroll; choose a different 2FA method; or elect not to use 2FA.”

This, rather unsurprisingly if you ask me, created a wave of concern amongst both ordinary users and security experts on the social media platform. One asked whether not using 2FA meant their account would remain active; another asked whether there had been a security breach; and another asked whether this only impacted passkey users?

ForbesGmail Account Lockout Warning — Users Must Check This 1 Setting Now

The confusion sat with X warning that “all accounts that use a security key as their two-factor authentication method to re-enroll their key to continue accessing X,” and adding that users could “re-enroll your existing security key, or enroll a new one.” A typical example of someone who knows what they are talking about but not how to communicate that in such a way to people who do not. Translating tech-speak into ordinary language is an essential skill and one that the X safety team appears to have misplaced on this occasion.

What X should have said, and ended up being forced into actually saying a day later, was: “To clarify: this change is not related to any security concern, and only impacts Yubikeys and passkeys – not other 2FA methods (such as authenticator apps). Security keys enrolled as a 2FA method are currently tied to the twitter.com domain. Re-enrolling your security key will associate them with x.com, allowing us to retire the Twitter domain. If this relates to you, you’ll be prompted automatically to re-enroll.”

ForbesOrganizations Can’t Deploy Passwordless, Declare Victory And Walk Away





Source link

Continue Reading

Tech

Google’s Pixel 10 Series Could Soon Receive A Significant Performance Boost

Published

on


Key Takeaways

  • Some Pixel 10 users have reported underperforming graphics and battery life.
  • Google has confirmed it will release driver updates, potentially addressing these issues and unlocking the Pixel 10’s full potential.
  • A new GPU driver update (version 25.2) is available that Google could deploy for significantly improved performance.

October 26 Update Below: A driver update may be essential for security reasons. This article was originally published on October 24

The Pixel 10 could soon receive a significant boost in performance, and potentially battery life, thanks to an upcoming graphics driver upgrade.

Reports indicate that the Pixel 10 series currently underperforms in graphics performance, notably scoring lower than the Pixel 9 Pro in some benchmark tests. The Pixel 10 series uses a PowerVR DXT-48-1536 GPU from Imagination Technologies, rather than the ARM Mali component found in previous models, which has led to complaints of poor performance, especially when playing popular, graphically intensive games such as Genshin Impact, and reduced battery life during video playback in apps like Netflix.

A primary cause of these performance issues appears to be an outdated GPU driver. The Pixel 10 shipped with driver version 24.3, lacking key features and optimizations necessary for the new GPU to reach its full potential. While it’s not unusual for a smartphone to ship with slightly older drivers, the switch from Mail to PowerVR appears to have exacerbated the issue.

A New GPU Driver Is Already Available

Fortunately, Imagination Technologies has since released driver version 25.2, adding official support for Android 16, along with significant performance enhancements, including support for the latest Vulkan 1.4 specification. That means this particular update could greatly benefit Pixel 10 users, and early indications suggest Google will most likely implement it.

A Google representative recently confirmed to Android Authority that the company plans to continue releasing GPU driver improvements in its regular system updates.

“We are continuing to improve driver quality in our monthly and quarterly system updates. For example, the most recent September and October patch releases included driver improvements. In future releases we are planning further GPU driver updates.”

Google has a strong track record in this area, having delivered a significant GPU performance boost for Pixel 8 Pro users in its December 2023 update, and several generations of Pixel smartphones received performance gains thanks to an updated GPU driver in the March 2025 Feature Drop. However, Google’s statement stops short of any commitment to any specific driver versions or performance benefits for the Pixel 10 range.

Google Pixel 10: Performance Upgrades Are Likely

If this pattern continues, Pixel 10 users can expect significant performance gains with future driver updates. Given that the new driver is already available from Imagination Technologies, we can hope it arrives sooner rather than later. For those currently experiencing graphics performance issues, a fix appears to be on the horizon.

October 26 Update: Existing vulnerabilities make a driver update extremely likely.

Driver updates typically offer not only performance improvements but also essential security patches, increasing the urgency of releasing updates.

The Pixel 10’s GPU driver is vulnerable, putting additional pressure on Google to provide an update.

According to Imagination Technologies’ published GPU Driver Vulnerabilities list, versions of the PowerVR GPU driver, up to and including version 24.3, currently deployed in the Pixel 10 series, contain critical vulnerabilities that could result in system instability, reboots and non-privileged access to secure data.

Addressing these vulnerabilities will be a high priority for Google, making a driver update urgent. Imagination Technologies doesn’t appear to have released any driver updates between versions 24.3 and 25.1, which fixes all of the listed vulnerabilities and adds most of the improvements listed in this article.

This means Google’s next Pixel 10 GPU driver update will likely be to least version 25.1, if not the latest version 25.2 released to partners on Oct 8. Pixel 10 Users can therefore expect significant improvements in performance, reliability and security once Google releases this update.

Follow @paul_monckton on Instagram.

ForbesNano Banana AI Image Editing Comes To Billions Of Google UsersForbesGoogle Photos’ New Update Leaves International Users Wanting More





Source link

Continue Reading

Trending