Friday, August 28, 2026
Follow on LinkedIn

Information Security

WordPress To Mandate 2FA for Theme And Plugin Developers

Beginning on October 1st, 2024, WordPress will mandate two-factor authentication (2FA) for plugin and theme creators as a new security measure. Themes and plugins that are used by millions of WordPress websites worldwide can be updated and changed by accounts...

Payment Gateway Platform SLIM CD Data Breach, 1.7 Million Users Data Exposed

The Slim CD, Inc., a prominent payment processing gateway for US and Canadian merchants, has disclosed a data breach affecting approximately 1.7 million users. The unauthorized access between August 17, 2023, and June 15, 2024, potentially exposed sensitive credit card...

New Emansrepo Malware Weaponizing HTML Files To Attack Windows Users

Emansrepo is a Python infostealer that was discovered by the FortiGuard Labs in August 2024 and has been disseminated through phishing emails containing fake purchase orders and invoices. It started its operation in November 2023, where Emansrepo retrieves exfiltrated data...

Hackers Delivers Lumma Stealer Via Public GitHub Commands

Threat actors often target the popular code repository platform "GitHub" due to it's wide use, and features that this platform offers. Cybersecurity analysts at Gen DIgital recently discovered that threat actors are exploiting GitHub to propagate an information stealer, 'Lumma.'  This...

Iran State-Sponsored Hackers Intelligence Operations Using Fake Job Offers

Mandiant has discovered one of the unusual Iranian counterintelligence activities that focuses on prospective agents of foreign intelligence services, especially in Israel. The operation was run by Iranian state-sponsored hackers between 2017 and March 2024 and comprised over 35 Farsi-language...

GitHub Vulnerability “ArtiPACKED” Trigger RCE Exploit to Hack Repositories

The research identifies a critical security vulnerability in GitHub Actions artifacts, enabling unauthorized access to tokens and secrets within CI/CD pipelines.  Misconfigured workflows in major organizations' public repositories exposed sensitive information, potentially compromising cloud environments and allowing attackers to inject...

Sonos Smart Speaker Vulnerability Let Attackers Execute Remote Code

In the beginning of August 2024, Sonos released a security advisory in which they fixed two security vulnerabilities that were associated with Remote Code Execution. These vulnerabilities have been assigned with CVE-2023-50810 and CVE-2023-50809.  These vulnerabilities were existing in Sonos...

ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

A massive data breach involving ClickBalance, one of Mexico's largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by cybersecurity researcher Jeremiah Fowler. The breach exposed a staggering 769,333,246 records, totaling 395 GB of data, in a non-password-protected...

Critical Splunk Vulnerability Exploited Using Crafted GET Commands

Splunk Enterprise is one of the many applications Splunk offers for security and monitoring purposes. It allows organizations to search, analyze and visualize data which can help to respond to incidents in a better way. However, at the beginning of...

Hackers Leveraging Compiled V8 JavaScript In Wild To Deploy Malware

Hackers exploit compiled V8 JavaScript to obfuscate their malicious code, as the compiled bytecode effectively hides the malware's original source code and intentions. Recently, the use of compiled V8 JavaScript by malware authors has been investigated by Check Point Research....

Latest News

Latest News