Cybersecurity

ShapedPlugin WordPress Backdoor in Supply Chain

Pro versions of three ShapedPlugin WordPress extensions were backdoored after attackers hijacked the official vendor distribution channel.The injected malware steals admin credentials, 2FA codes,...

Critical Flaws in Dify AI Platform Expose User Data

Critical vulnerabilities in the popular open-source AI platform Dify could have allowed attackers to secretly wiretap and steal AI chat conversations from other customers'...

Canada’s spy agency hacked, neutralized state-linked botnets

For the first time, CSIS used its legal "threat reduction" powers to disrupt foreign state-run botnets residing on infected Canadian devices.The Federal Court authorized...

AryStinger Botnet Hijacks Old Routers for Spying

A new malware called AryStinger has infected at least 4,300 older home routers, according to research from QiAnXin's XLab.Instead of creating a typical DDoS...

WordPress Gravity SMTP Bug Exploited, API Keys Stolen

A WordPress plugin flaw exposes API keys and system data on roughly 100,000 sites.The vulnerability allows unauthenticated attackers to harvest credentials for email services.Over...

Apple A12/A13 SecureROM Flaw Unpatchable

A working exploit achieves arbitrary code execution within the SecureROM of Apple's A12 and A13 chips, a flaw burned into the silicon.Affected devices, including...

Salesforce disables Klue app after data breach

Security firm Klue suffered a breach via a legacy credential, allowing hackers to steal OAuth tokens and access customer data on integrated platforms.The incident...

Fake Reviews Boost Crypto-Stealing Malware Campaign

Malicious actors are creating a "fake reputation economy" by using coordinated reviews, social media buzz, and paid news articles to promote malware.The goal is...

Latest news

CoinEx Denies $3.8B Iranian Crypto Flow Allegations

TRM Labs alleges over $3.84 billion in crypto flowed between CoinEx and more than 60 sanctioned Iranian platforms over...

ZAN Joins Theta Network as Strategic Enterprise Validator

ZAN, the Web3 brand of Ant Digital Technologies, has joined the THETA Network as a strategic Enterprise Validator Node...

Bithumb fined for sending user data overseas

South Korea's Personal Information Protection Commission fined Bithumb $136,000 for sending user data overseas without proper consent.The breach involved...