PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
20 articles
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
OPSWAT researchers find two zero-days in TP-Link cameras
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection