Hacker targets GitHub users with trojanized code laced with backdoors
The GitHub account ‘ischhfd83,’ which published Sakura RAT, was linked to a broader malware distribution network spanning 141 repos.
The GitHub account ‘ischhfd83,’ which published Sakura RAT, was linked to a broader malware distribution network spanning 141 repos.
Some of the fake DocuSign pages deploy a deceptive CAPTCHA verification process.
The breach came to light when a TaskUs employee was caught photographing her computer screen with a personal device.
The researchers found that native Android apps silently listen on fixed local ports for tracking purposes.
The flaws allow attackers to steal PIN codes, perform unauthorized factory resets, and gain system-level access.
The threat actors are compromising services like Docker, Gitea, and HashiCorp’s Consul and Nomad platforms.
The flaw could allow attackers to corrupt memory on the heap via specially crafted HTML pages, potentially leading to remote code execution.
The initiative aims to standardize the confusing nicknames used by cybersecurity firms to track digital adversaries.
CVE-2025-48827 and CVE-2025-48828 affect vBulletin versions 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 running on PHP 8.1 or newer.
One of BitMEX's employees was targeted on LinkedIn by a fake recruiter promoting a job at an NFT project.
Showing elements 701 - 710