Aggregator
Java SPI机制攻击
WhatsApp phishing attack uses fake business docs to hack PCs
Kilo-Org kilocode (CVE-2026-8766)
「幻核-3」向Linux程序注入代码而文件大小不变
关于某池WAF SQL 注入绕过可行性探究
Actf2026 Web AAA'26
LitCTF2026 web方向全解
JDK 21 强封装突破:从 Unsafe 到 IMPL_LOOKUP 的权限提升利用链
PHP WebShell 免杀之字符串运算 + 动态调用
Court rules SAVE database illegal, orders it dismantled
A judge said the administration’s database violates the Privacy Act, the Social Security Act and the Administrative Procedures Act.
The post Court rules SAVE database illegal, orders it dismantled appeared first on CyberScoop.
Safepay
You must login to view this content
JaredFromSubway MEV bot hacked in $15 million crypto theft
Brain Cipher
You must login to view this content
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
FFmpeg fixes PixelSmash flaw in widely used video decoder
Qilin
You must login to view this content
23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools
A new supply chain threat has surfaced in the AI agent ecosystem that is both subtle and serious. Researchers uncovered 23 plugins on the ClawHub registry published under official organizational scopes without any authorization from ClawHub or its parent project, OpenClaw. These plugins used trusted namespace prefixes to look like genuine, first-party tools, while they […]
The post 23 ClawHub Plugins Abuse Official Org Scopes to Impersonate Trusted AI Agent Tools appeared first on Cyber Security News.
Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection
A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The attack is subtle, well-crafted, and far more dangerous than it first appears. The infection begins […]
The post Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection appeared first on Cyber Security News.
Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader
A sophisticated phishing campaign is actively targeting users in India by disguising malware as a routine GST debit note. The attack delivers a powerful remote access tool called Remcos RAT through a cleverly constructed multi-stage loader, giving attackers deep and persistent control over infected systems. What makes this threat especially alarming is how the entire […]
The post Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader appeared first on Cyber Security News.