Scope Squatting Vulnerability Exposed in ClawHub Plugin Registry
A recently disclosed supply chain weakness in ClawHub's plugin registry allowed third-party developers to publish plugins under organizational namespaces they did not own. As a result, unofficial plugins appeared to [...]
Critical Splunk AI Toolkit Vulnerability Discovered
Splunk has released a security update to address a critical vulnerability in its AI Toolkit that could allow attackers with administrative access to run unauthorized operating system commands on affected [...]
F5 NGINX Vulnerabilities Patched in Critical Security Update
F5 has issued an emergency security advisory addressing several vulnerabilities affecting NGINX products and related components. The flaws could allow attackers to disrupt services, crash applications, or potentially execute malicious [...]
Hackers Use GitHub Pages for Phishing Attacks
Researchers have uncovered a sophisticated phishing campaign targeting banking customers in Mexico through a highly scalable and resilient attack infrastructure. The operation leverages GitHub Pages to host convincing phishing websites [...]
Sapphire Sleet Targets macOS With Multi-Stage Malware
Researchers have uncovered a new macOS malware campaign linked to the North Korean threat group known as Sapphire Sleet. The attackers are using fake software update files disguised as Zoom [...]