keyv npm supply chain attack on August 4, 2026 let the Shai-Hulud worm compromise 400-plus packages and more than two billion ...
WordPress fixes CVE-2026-64638, a pre-auth login XSS affecting every version, with a demonstrated path to PHP execution under ...
BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
Tenet Security showed how a publicly exposed error-tracking credential and an MCP integration chain into remote code ...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
FortiGuard exposes year-long QuickFox VPN supply chain attack deploying FDMTP implant on corporate Windows machines only.
A malicious change was made to the legitimate QuickFox VPN installer, allowing it to secretly download a backdoor onto ...
Laundry Bear exploits security flaw in unpatched Zimbra servers, stealing 90 days of emails and authentication data without ...
A Mini Shai-Hulud worm spread through more than 400 npm packages, stealing npm, GitHub, cloud, and CI/CD credentials.
Seqrite warns that attackers are using SVG files to hide malicious JavaScript and phishing redirects, creating a new security ...
SaaS platforms, CRM and ERP systems, and collaboration tools have made the browser the primary gateway, and often the central ...