“At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and
Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including their repositories and members.
The post Ghost Accounts Abuse GitHub API in Mass Recon Campaign appeared first on SecurityWeek.
Australia warns of global campaign targeting vulnerable CMS platforms
‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user’s session. It has yet to be assigned a CVE identifier.
“The
New U-Boot flaws could enable stealthy firmware attacks
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
Police suspects Dutch hackers were involved in Odido breach
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
The company has temporarily disabled access to the affected accounts, a step it says it took “out of an abundance of caution” while it works with internal and external security
