This Week in Cybersecurity: Looking Back at Week 4
CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List Hundreds of Fake Reddit Sites Push Lumma Stealer Malware Ivanti Vulns Chained Together in Cyberattack Onslaught SonicWall Warns of SMA1000 RCE Flaw Exploited in Zero-Day Attacks Stealthy ‘Magic Packet’ Malware Targets Juniper VPN Gateways Fake Homebrew Google Ads Target Mac Users with Malware CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a now-patched cross-site scripting (XSS) vulnerability (CVE-2020-11023) affecting the widely-used jQuery JavaScript library to its Known Exploited Vulnerabilities (KEV) catalog.