Aggregator
Critical Backdoor Exposes 20,000 WordPress Sites to Complete Takeover
A severe backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor WordPress plugin, enabling threat actors to […]
The post Critical Backdoor Exposes 20,000 WordPress Sites to Complete Takeover appeared first on HawkEye.
CVE-2025-13002 | Farktor E-Commerce Package up to 27112025 cross site scripting
CVE-2025-13004 | Farktor E-Commerce Package up to 27112025 authorization
CVE-2025-10969 | Farktor E-Commerce Package up to 27112025 sql injection
CVE-2026-2007 | PostgreSQL 18.0/18.1 pg_trgm heap-based overflow
CVE-2026-2004 | PostgreSQL up to 14.20/15.15/16.11/17.7/18.1 intarray Extension improper validation of specified type of input
CVE-2026-2006 | PostgreSQL up to 14.20/15.15/16.11/17.7/18.1 Multibyte Character array index
CVE-2026-2003 | PostgreSQL up to 14.20/15.15/16.11/17.7/18.1 oidvector improper validation of specified type of input
CVE-2026-2005 | PostgreSQL up to 14.20/15.15/16.11/17.7/18.1 pgcrypto heap-based overflow
Highguard 开发商裁掉大部分员工
World Leaks Ransomware Group Adds Stealthy, Custom Malware ‘RustyRocket’ to Attacks
DeepAudit开源AI代码审计系统漏洞分析
WhatsApp says Russia tried to fully block platform, push users to state app
Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users
A dangerous malware campaign has emerged on the NPM package registry, putting thousands of developers and Windows users at risk. The malicious package, known as “duer-js,” was published by a user named “luizaearlyx” and disguised itself as a legitimate console visibility tool. Despite having only 528 downloads, security experts warn that its sophisticated attack methods […]
The post Sophisticated ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users appeared first on Cyber Security News.