A critical vulnerability in cPanel could allow hosting customers to run SQL queries with database root privileges. This flaw threatens the security of shared hosting environments, potentially exposing sensitive data across multiple accounts. Hosting providers should apply updates immediately.
Security researchers discovered 18 malicious npm packages that deliver a cross-platform remote access trojan (RAT) to users of Alibaba cloud development tools. The packages masquerade as legitimate dependencies, and once installed, they can steal sensitive data or enable remote control. This highlights an ongoing supply chain risk in the open-source ecosystem.
Security researchers have discovered attack methods that let malware abuse Google Password Manager to steal passkeys and take over protected accounts. These techniques bypass the intended protections of passkey-based authentication, which is increasingly used as a safer alternative to passwords. The findings highlight a critical weakness in how passkeys are stored and accessed, urging users to stay alert to malware risks.
INC ransomware has emerged as the most dominant threat actor exploiting vulnerabilities in SonicWall SMA 1000 devices. This gives the group a reliable entry point into corporate networks, significantly raising ransomware risks for affected organizations.
A breach of the Police National Legal Database (PNLD) has leaked contact details of U.K. police and government personnel onto the dark web. The exposed information could be used for targeted phishing and social engineering attacks against officials. This highlights serious security concerns over sensitive law enforcement data handling.
N-able disclosed that attackers gained full control of N-central servers after an initial security fix proved incomplete. The remote monitoring platform is widely used by managed service providers, so a server takeover could expose client networks downstream. The company is urging customers to apply a new patch and check for signs of compromise.
Security researchers disclosed multiple flaws in Hugging Face's Diffusers library that could allow malicious model repositories to execute arbitrary code when loaded. The vulnerabilities stem from unsafe deserialization and mishandled pickle files. Users are urged to update to patched versions to prevent supply-chain attacks.
A critical vulnerability in Coldcard hardware wallets was exploited to steal approximately $70 million in Bitcoin within 41 minutes. The attack highlights the risks of relying on hardware wallet security, prompting urgent user action to secure affected funds.
Threat actors compromised a script from Adform, a digital advertising platform, and used it to inject malicious code that swaps cryptocurrency wallet addresses on customer websites. This supply-chain attack could divert funds from numerous sites that rely on Adform's infrastructure. The incident highlights risks associated with third-party scripts in online transactions.