Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A supply chain attack targeted BdThemes WordPress plugins by poisoning a remote JSON data stream used for promotional banners. The injected cross-site scripting payload created rogue administrator accounts and installed a web shell, all without altering plugin source code.
This advisory describes a denial-of-service vulnerability in multiple F5 products, including BIG-IP Next and BIG-IP DNS. No patch exists, so F5 provides workarounds such as restricting upstream DNS servers and enabling DNS-over-TLS. Organizations should review the vendor advisory and apply mitigations.
Attack TTPs combine fileless execution, wide LOLBin useCategories: Threat Research
Lures on compromised WordPress sites led to installation of Deno and a Python-based infostealerCategories: Threat ResearchTags: clickfix, Deno, WordPress
Hackers breached a small Polish energy plant last year by using a private APN to access its operational technology network. The heat-and-power facility supplies heat to roughly 50,000 residents, highlighting the serious consequences of insecure OT remote access.