KongTuke FileFix Leads to New Interlock RAT Variant
Researchers identified a new PHP-based variant of the Interlock ransomware group's RAT, shifting from JavaScript-based NodeSnake, used in widespread attacks since May 2025.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,611 stories synthesized.
Researchers identified a new PHP-based variant of the Interlock ransomware group's RAT, shifting from JavaScript-based NodeSnake, used in widespread attacks since May 2025.
Jenkins released a security advisory covering 20 plugins, addressing vulnerabilities ranging from credential exposure and stored XSS to arbitrary value injection, with patches now available.
GitLab released versions 18.1.2, 18.0.4, and 17.11.6 on July 9, 2025, fixing four security vulnerabilities including a high-severity cross-site scripting issue (CVE-2025-6948) and three authorization bypass flaws.
The DFIR Report details an intrusion that began with a password spray attack against an internet-facing RDP server, culminating in the deployment of RansomHub ransomware across the victim's network.
GitLab released versions 18.1.1, 18.0.3, and 17.11.5 on June 25, 2025, fixing six security vulnerabilities, including a medium-severity flaw allowing unauthenticated file uploads to public projects.
WordPress will stop providing security updates for versions 4.1 through 4.6 as of July 2025, urging remaining users to upgrade.
The threat group 'The Com' is exploiting Salesforce app authorization abuse through social engineering, targeting tenants for data theft and extortion.
GitLab released versions 18.0.2, 17.11.4, and 17.10.8 on June 11, 2025, fixing multiple security vulnerabilities including three high-severity issues that could enable account takeover, cross-site scripting, and malicious CI/CD job injection.
Jenkins released a security advisory for a high-severity XSS vulnerability in the Gatling plugin that bypasses CSP protections, with no fix currently available.
A threat actor group with tactics similar to Scattered Spider is hijacking DNS MX records to redirect enterprise email traffic to attacker-controlled servers, enabling credential theft and network compromise within minutes.
GitLab released versions 18.0.1, 17.11.3, and 17.10.7 on May 21, 2025, fixing multiple security vulnerabilities including a high-severity unauthenticated denial-of-service flaw and a SAML response manipulation bug that bypasses two-factor authentication.