WordPress Plugin Vulnerabilities Enable RCE
A large-scale cyber campaign is actively exploiting known vulnerabilities in content management systems (CMS), with WordPress plugins being the primary target. Attackers are scanning the internet for vulnerable websites and [...]
GitHub Signature Flaw Enables Duplicate Verified Commits
A recently disclosed security finding has revealed that attackers can create duplicate "Verified" GitHub commits by exploiting a technique known as signature malleability. Although the duplicated commit is assigned a [...]
SindriKit 1.3.0 Bypasses EDR Security
A new version of SindriKit (1.3.0) introduces advanced techniques designed to evade modern Endpoint Detection and Response (EDR) solutions. Earlier versions focused on using indirect system calls to bypass user-mode [...]
Malicious AI Skills Threaten Enterprise Security
Security researchers have discovered that malicious AI agent skills can be designed to steal credentials, extract source code, and install backdoors while avoiding detection by many existing security scanning tools. [...]
Opera GX Flaw Allows CSS Injection
Security researchers have uncovered a critical vulnerability in Opera GX that could allow attackers to inject malicious CSS across every webpage a victim visits. The issue affects the browser's GX [...]