Skip to content
category — security

ls ./category/security --page 2

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 2 of 9 — 211 articles

The WordPress backdoor lives in eight places at once, and each one rebuilds the others

2026-10-02

Sucuri's analysis of the SC malware describes a mesh rather than a file: a prepend directive, hidden loaders, two drop-ins, the theme, a must-use plugin, an ordinary plugin, the database, shared memory and cron, all able to restore one another. Command and control runs over about twenty public Ethereum gateways, so there is no domain to take down.

Bitget lost about 388 million dollars, and the way in was the security product

2026-10-01

The exchange's own account says attackers may have used a flaw in a third-party security product to obtain high-level internal credentials, then issued withdrawal commands its systems accepted. Mandiant and SlowMist are reported to date the access to 31 August, three and a half weeks before the transfers. Cold wallets were untouched and private keys were not taken.

France's tax agency learned of the theft from the thief, seven weeks after it started

2026-10-01

ANSSI's incident report on the DGFiP, published on 29 September, describes several dozen agent passwords stolen from machines the agency does not manage, sensitive portals with no multi-factor authentication, and a messaging tool scraped on three days in June and July. Nobody noticed until the attacker posted about it on a forum on 12 August.

The CPU forgets the code and remembers where it jumped. That is enough to read the root hash

2026-10-01

VUSEC's Branch Target Reuse attack uses a gap nobody closed: when a JIT engine throws away compiled code and writes new code in the same place, the processor updates what is there but keeps its old prediction of where the jump goes. On a fully patched Intel machine with default mitigations, their Linux exploit pulls the root password hash out of kernel memory at eight bytes a second.

The call is about your passkey. The break-in uses routes a passkey alone does not close

2026-09-15

Microsoft says extortion groups tied to ShinyHunters and Helix are phoning staff about urgent passkey or single sign-on updates, then steering them into relayed sign-ins or device-code approvals. Once in, they register an MFA method of their own, map the tenant through Microsoft Graph and take files at under 1,000 an hour to stay unremarkable.

The Trezor phishing needed no stolen password. Brevo's SSO let the attacker sign in as the people they invited

2026-09-15

Phishing that reached 347,000 Trezor newsletter subscribers came from Trezor's genuine Brevo account, so it passed every sender check. Brevo's post-mortem says the attacker created an account, switched on single sign-on, invited real Brevo users into it, and was then let into every organisation those users could reach. Early coverage spoke of stolen login details. Brevo's account involves none.