Information Security

WordPress To Mandate 2FA for Theme And Plugin Developers

Beginning on October 1st, 2024, WordPress will mandate two-factor authentication (2FA) for plugin and theme creators as a new security…

2 years ago

Payment Gateway Platform SLIM CD Data Breach, 1.7 Million Users Data Exposed

The Slim CD, Inc., a prominent payment processing gateway for US and Canadian merchants, has disclosed a data breach affecting…

2 years ago

New Emansrepo Malware Weaponizing HTML Files To Attack Windows Users

Emansrepo is a Python infostealer that was discovered by the FortiGuard Labs in August 2024 and has been disseminated through…

2 years ago

Hackers Delivers Lumma Stealer Via Public GitHub Commands

Threat actors often target the popular code repository platform "GitHub" due to it's wide use, and features that this platform…

2 years ago

Iran State-Sponsored Hackers Intelligence Operations Using Fake Job Offers

Mandiant has discovered one of the unusual Iranian counterintelligence activities that focuses on prospective agents of foreign intelligence services, especially…

2 years ago

GitHub Vulnerability “ArtiPACKED” Trigger RCE Exploit to Hack Repositories

The research identifies a critical security vulnerability in GitHub Actions artifacts, enabling unauthorized access to tokens and secrets within CI/CD…

2 years ago

Sonos Smart Speaker Vulnerability Let Attackers Execute Remote Code

In the beginning of August 2024, Sonos released a security advisory in which they fixed two security vulnerabilities that were…

2 years ago

ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

A massive data breach involving ClickBalance, one of Mexico's largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by…

2 years ago

Critical Splunk Vulnerability Exploited Using Crafted GET Commands

Splunk Enterprise is one of the many applications Splunk offers for security and monitoring purposes. It allows organizations to search,…

2 years ago

Hackers Leveraging Compiled V8 JavaScript In Wild To Deploy Malware

Hackers exploit compiled V8 JavaScript to obfuscate their malicious code, as the compiled bytecode effectively hides the malware's original source…

2 years ago