Linux Rootkit Hides Fileless PHP Web Shells in F5 BIG-IP Server Memory
A sophisticated Linux rootkit is targeting F5 BIG-IP Access Policy Manager servers, injecting fileless PHP web shells directly into server memory to maintain persistent access.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,158 stories synthesized.
A sophisticated Linux rootkit is targeting F5 BIG-IP Access Policy Manager servers, injecting fileless PHP web shells directly into server memory to maintain persistent access.
Online maths learning platform Mathspace has confirmed a data breach impacting over 1 million users, stemming from attackers exploiting a critical SQL injection vulnerability in its Metabase reporting software.
Check Point Research's latest threat intelligence report highlights breaches at Thomson Reuters and Dropbox, an AI-assisted ransomware attack, and critical vulnerabilities in SonicWall and JFrog products.
Switzerland's federal administration is testing a sovereign, open-source digital workplace to decrease dependence on Microsoft 365, aiming for enhanced digital sovereignty and resilience.
This week's security landscape was shaped by actively exploited zero-days in Chrome and MikroTik routers, a supply chain attack targeting e-commerce platforms, and novel evasion techniques.
Microsoft is phasing out Manifest V2 browser extensions in Edge by early 2027, mandating a transition to Manifest V3 to enhance security and performance.
Key findings • Twelve vulnerabilities disclosed for MISP between Sept 6-7, 2026, focusing on authorization bypasses and input validation. • Four high-severity flaws identified, including issu…
A new Linux botnet malware named Tengu is designed to evade detection by masquerading as a kernel process, targeting servers, embedded systems, and IoT devices with DDoS capabilities.
Researchers uncover Bring Your Own Trusted Caller (BYOTC), a novel Windows attack technique that exploits the trust relationship between legitimate applications and privileged kernel drivers to disable security tools.
Researchers allege that certain LG OLED smart TVs scan home networks and capture microphone audio even when in standby mode, uploading the data later.
Approximately $320 million in Bitcoin was drained from the Liquid Network's federation wallet by attackers claiming to be white-hat hackers seeking to fix a vulnerability.
The Kimsuky threat group is employing an AI agent named OpenCode to rapidly generate sophisticated phishing decoys, increasing the scale and speed of their attacks.
Key findings • Ten vulnerabilities disclosed for Tenda devices between September 5-7, 2026. • Critical flaws include OS command injection, buffer overflows, and improper authentication across…
Berlin is investigating a second data leak after hackers published stolen login credentials and other sensitive information online, following a mid-August breach of city government networks.
A new analysis of misconfiguration data from 3,000 organizations reveals that common cloud security risks vary widely between AWS, Azure, and Google Cloud, rendering one-size-fits-all strategies ineffective.
Researchers are investigating the use of AI by promoters on X (formerly Twitter) to engage users in flirtatious conversations and drive traffic to adult content pages.
Key findings • Three low-severity vulnerabilities in HCL MyXalytics disclosed on September 7, 2026. • Vulnerabilities include potential DoS, content spoofing, and improper input validation. …
Natural Resources Wales inadvertently disclosed sensitive diversity data for approximately 2,000 current and former employees online, prompting an apology and investigation.
Sekoia and Kudelski Security have identified six distinct cyber clusters operating under the umbrella of North Korea's Lazarus threat group, each specializing in espionage, financial theft, and sanctions evasion.
Roundcube Webmail has released versions 1.6.19 and 1.7.4 to address 12 vulnerabilities, including a zero-click stored XSS, XSS in the HTML editor, and multiple email header injection flaws.
A counterfeit Minecraft optimization mod is distributing the Myth Stealer RAT, which steals browser credentials and cookies, masking its malicious intent with functional game enhancements.
Key findings • Three MISP vulnerabilities, including two high-severity flaws, were disclosed together between Sept 6-7, 2026. • Flaws include improper authorization checks and ACL bypasses in…
A UK watchdog has identified cyberattacks as a significant and growing threat to the nation's food supply chain, citing recent disruptions at major retailers.
A chain of four vulnerabilities in Telerik UI for ASP.NET AJAX allows unauthenticated attackers to achieve remote code execution, impacting versions from 2010 to 2026.