Tag: security

Faulty Shopify plugin puts hundreds of websites at risk of invasive attacks – find out how to stay safe

Consentik, a cookie consent & consent management app for Shopify, kept sensitive data in an open archive The archive was available for at least 100 days, if not more It included site analytics data, Shopify Personal Access Tokens, and Facebook Auth Tokens A major, reputable Shopify plugin, was leaking sensitive…

Read More

North Korean hackers release malware-ridden packages into npm registry

Security researchers spotted 67 malicious packages on npm The packages are part of the Contagious Interview campaign They are most likely deployed by North Korean attackers North Korean hackers have been seen pushing dozens of malicious packages to npm in an attempt to compromise western technology products through supply chain…

Read More

UK launches new Vulnerability Research Institute to protect critical infrastructure and UK business

VRI will complement NCSC’s current vulnerability research efforts It will be tasked with communicating NCSC’s needs with external experts The goal is to understand the flaws, patches, and research methodology The UK’s National Cyber Security Centre (NCSC) just announced the forming of The Vulnerability Research Initiative (VRI), a new program…

Read More

Google Gemini can be hijacked to display fake email summaries in phishing scams

Gemini in Workspace presents unique opportunities for fraud, researchers warn The AI tool can be tricked to display fake security warnings Businesses should make sure invisible text is not processed by the AI Cybercriminals have found a creative new way to abuse Google’s Generative Artificial Intelligence (GenAI) to steal people’s…

Read More

A major security flaw in top eSIM system could put billions of devices at risk – here’s what we know

A test eSIM profile used by billions of devices carried a major flaw It allowed malicious actors with physical access the ability to deploy applets A patch is now available, so users should upgrade now Security researchers have discovered a vulnerability in eSIM technology used in virtually all smartphones and…

Read More

WordPress users beware – this popular plugin has been hijacked to push potential malware

The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for two days The variant harvested extensive information and allowed for RCE The malware affected only manual downloads and composer installations Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a…

Read More