Tag: security

Top WordPress Slider plugin hijacked to spread malware — here’s what to look out for

Smart Slider 3 plugin update compromised with backdoors Malicious version 3.5.1.35 pushed to 800,000+ sites Nextendweb urges rollback or upgrade to clean release If you are using the Smart Slider 3 plugin for either WordPress or Joomla, make sure to update immediately, as experts have warned the tool was recently…

Read More

Breach exposes sensitive LAPD files stored in city attorney system

Hackers breached LA City Attorney’s Office systems 337,000 LAPD files stolen, including personnel and internal affairs data Group “World Leaks” published archive, later removed Cybercriminals have reportedly broken into the Los Angeles City Attorney’s Office and stolen sensitive data belonging to the Los Angeles Police Department. The LA Times reported…

Read More

‘FlamingChina’ hacker claims to have stolen over 10 petabytes of advanced military data from China’s National Supercomputing Center in possibly the biggest hack of all time

‘FlamingChina’ claimes 10PB of data was stolen from the supercomputer The supercomputer was used by numerous military and civilian entities Samples of the data show simulations of aircraft, missiles, and bombs An individual or group calling itself ‘FlamingChina’ claims to have stolen over 10 petabytes of highly sensitive military information…

Read More

Now that’s different – hackers use miniature SVG images to try and hide credit card stealer

Experts find credit card skimmer hidden in 1×1 SVG image Fake “Secure Checkout” overlay stole card data Likely exploited Magento PolyShell flaw, affecting many stores Security researchers recently found a credit card skimmer on almost a hundred compromised ecommerce websites hiding in a tiny image. Experts from Sansec reported finding…

Read More

Top open source AI platform Flowise hit by maximum-level security issue

Flowise AI platform carried CVSS-10 arbitrary code flaw Vulnerability in CustomMCP node exploited in the wild Up to 15,000 exposed instances urged to update immediately Flowise, a popular open source platform for building custom LLM apps and AI agents, carried a maximum-severity vulnerability which allowed threat actors to run arbitrary…

Read More

Snowflake customers suffer data theft attacks after third-party issue, company confirms ‘unusual activity’

ShinyHunters breached Anodot, stealing Snowflake tokens Attack hit more than a dozen Snowflake customers Group claims data theft and extortion, echoing 2024 campaign A supply chain attack at an analytics company has resulted in more than a dozen Snowflake customers losing their sensitive information. The ShinyHunters extortion group recently broke…

Read More