Information Security News Blog

ShinyHunters hacking group conceptual image illustrating WAF evasion targeting Oracle PeopleSoft 0

ShinyHunters Resurges with Advanced Oracle PeopleSoft Attacks

The notorious ShinyHunters cybercriminal syndicate has aggressively resumed mass exploitation campaigns explicitly targeting Oracle PeopleSoft infrastructure. Alarmingly, they have engineered sophisticated methodologies to seamlessly bypass the defensive countermeasures organizations frantically erected following the initial...

Cross-platform sckit worm infection vector bridging npm and PyPI ecosystems via MemTensor packages 0

The ‘sckit’ Worm Bridges the npm and PyPI Divide

An identical, highly sophisticated malicious program has successfully breached both sides of a major programming language divide simultaneously. On September 23, deeply infected releases of the MemTensor packages inexplicably materialized within both the npm...

CISA Known Exploited Vulnerabilities catalog listing for SharePoint and WSO2 0

CISA Catalogs Exploited Vulnerabilities Across Major Platforms

The United States Cybersecurity and Infrastructure Security Agency (CISA) recently expanded the CISA Known Exploited Vulnerabilities catalog, adding four critical flaws currently being weaponized in active, real-world cyberattacks. These devastating threats compromise Microsoft SharePoint...

Carbonato botnet Docker API exploitation and Hermes AI agent interface 0

Carbonato Botnet Exploits Exposed Docker API

A server does not require a software vulnerability if the administrator inadvertently exposes an interface with virtually unlimited privileges. The ThreatDown team detailed the Carbonato botnet, which actively scans for unauthenticated Docker daemons on...

Elementor WordPress plugin interface highlighting a CSRF vulnerability exploit 0

Critical Elementor CSRF Vulnerability Threatens Millions

A seemingly innocuous link possesses the terrifying potential to transform an active WordPress administrator session into a devastating site takeover mechanism. Cybersecurity researchers recently unearthed a profound vulnerability within the ubiquitous Elementor Website Builder....

Cloudflare Containers infrastructure diagram showing cross-tenant data vulnerability and thin provisioning 0

Cloudflare Resolves Cross-Tenant Data Exposure Flaw

A terminated container is theoretically engineered to vanish entirely, alongside all its ephemeral data. However, within Cloudflare’s sprawling infrastructure, fragments of this sensitive information inexplicably survived the previous owner of the physical disk block....

Fake Cloudflare CAPTCHA ClickFix interface leading to Psychedelic Stealer installation 0

Psychedelic Stealer Weaponizes Compromised Websites

A perilous trap may now await visitors upon seemingly familiar digital terrain: malicious actors have systematically compromised several legitimate Ukrainian websites, covertly embedding a fraudulent Cloudflare verification gateway. This deceptive interface cunningly orchestrates the...

CERT Polska AI analysis laboratory analyzing MikroTik RouterOS binary files 0

CERT Polska Dissects the MikroTrick RouterOS Exploit

Following MikroTik’s abrupt release of an emergency security update, the elite CERT Polska team required approximately one hour of forensic analysis to pinpoint the underlying critical vulnerability. By meticulously scrutinizing the architectural modifications within...