New Strain of Malware Poses as Legitimate WordPress Caching Plugin
A sophisticated backdoor disguised as a caching tool allows threat actors to create administrator accounts and gain complete control over compromised websites.
A sophisticated backdoor disguised as a caching tool allows threat actors to create administrator accounts and gain complete control over compromised websites.
A user named Disti has uploaded malicious NuGet packages on the package manager for the .NET Framework, including a typosquat of a legitimate package and several others that masquerade as crypto service libraries but actually deploy a remote access trojan (RAT), highlighting the exploitation of open-source ecosystems by attackers.
California Governor Gavin Newsom signs groundbreaking legislation that enables residents to request the deletion of their personal data from data brokers’ records with a single request, aiming to protect citizens’ online rights.
cURL has released Version 8.4.0 to address a high security impact vulnerability that allows for a heap-based buffer overflow during the SOCKS5 proxy handshake.
The US government, in collaboration with various agencies, has released new recommendations for securing open source software in critical infrastructure facilities and operational technology organizations.
The Balada Injector campaign has targeted and compromised over 17,000 WordPress websites, exploiting vulnerabilities in premium theme plugins and redirecting visitors to fraudulent pages.