BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
Beacon, a CRM provider for charities and nonprofits, says an AWS access key "potentially exposed in public JavaScript build artifacts" is the leading suspect in its July breach.
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
Seqrite warns that attackers are using SVG files to hide malicious JavaScript and phishing redirects, creating a new security ...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
China-linked Jewelbug uses XG-Web for espionage and crypto fraud, stealing over 580,000 browser cookies and thousands of ...
The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. Although the threat actor has targeted government ...
Kaspersky data shows 75 million cyberattacks blocked across APAC in the first half of 2026, including 3.4 million backdoor attacks, 2.4 million password stealers and 250,000 ransomware incident ...
Extortion gang Fulcrumsec has leaked on its dark web site a second large cache of data it allegedly stole in a June attack on Novo Nordisk. The latest data dump ...
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the ...
GPT-5.6-Cyber responded to 95% of advanced cyber requests in an OpenAI refusal-rate test and has been used to uncover previously unknown vulnerabilities in Google’s V8 engine.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results