Skip to content
category — security

ls ./category/security --page 5

Security

Breaches, vulnerabilities, malware and the patches that matter.

page 5 of 9 — 211 articles

Three of the ten most exploited weaknesses were called unforgivable in 2007

2026-09-01

CISA's review of 2024 and 2025 finds that the flaws attackers actually use are injection, input validation and path traversal — the same list as two decades ago. Seven of the ten most frequent weaknesses on the exploited-vulnerabilities catalog account for 41.5% of everything on it. CISA blames culture and workflow, not difficulty.

A state-linked backdoor for diplomats, written as a Windows batch file

2026-08-31

HOOKEDGE polls webhook.site for command files, runs them, and posts the output back as HTML. No custom infrastructure, no compiled binary, no exotic protocol — a .cmd script and a free service anyone can sign up for. Recorded Future ties it to APT28 with moderate confidence, and says so.

Five of the 19 malicious extensions were bought from their original developers

2026-08-31

Socket found 19 Chrome and Edge extensions draining wallets, harvesting hardware wallet seed phrases and stealing credentials. The operators wrote 14 of them and purchased the other five from previous owners — complete with existing users. Then they pushed an update, and Chrome installed it automatically.

The only thing they changed was telling you to open Terminal instead of Run

2026-08-31

TerminalFix is ClickFix with one substitution. A fake Cloudflare CAPTCHA asks you to paste a command, and instead of the Run dialog it sends you to Windows Terminal or PowerShell — where long multi-line scripts actually work. The end of the chain is a Python reverse tunnel that lets the operator reach anything your machine can see.

8,393 Gitea servers are exposed, and the flaw needs an account anyone can make

2026-08-31

CVE-2026-60004 lets a user with ordinary write access to a repository run shell commands as the Gitea system user. That reads as an authenticated flaw until you notice that Gitea ships with open registration, so a visitor can sign up, create a repository, and qualify. The fix has been out since 27 July. Miners are already running.

A 2023 flaw with a 2023 fix was used to take nuclear-material records this year

2026-08-31

CVE-2023-49105 lets anyone read, change or delete files on an ownCloud server without authenticating, if they know a username and the default configuration is in place. It was fixed in November 2023. It has now been used against a Philippine nuclear research body, and CISA added it to its exploited-vulnerabilities list on 27 August.

The ATF says it was a standalone system. Senior officials called it a major incident

2026-08-30

Qilin listed the Bureau of Alcohol, Tobacco, Firearms and Explosives on its leak site on 26 August. The ATF confirmed an intrusion into a standalone system it disconnected, and says its mission is unaffected. It also confirmed that senior Justice Department officials designated the event a major incident — a federal threshold with a definition.