Shai-Hulud: When npm Installs Became a Worm
Shai-Hulud Campaign: Why This Attack Is Different The Shai-Hulud campaign marks a turning point in how supply…
continue reading..
CVE-2025-11419: Red Hat Keycloak TLS Client-Initiated Renegotiation DoS
Vulnerability Header Attribute Details CVE ID CVE-2025-11419 CVSS Score 7.5 (High) Severity High / Important Published December…
continue reading..
CVE-2025-61882: Critical Oracle E-Business Suite Vulnerability Being Actively Exploited by Cl0p Ransomware Group
What’s Going On Right Now On December 23, 2024, Oracle issued a critical security advisory for a…
continue reading..
Stealka Infostealer: The Windows Malware Stealing Your Cryptocurrency and Passwords Right Now
What’s Actually Going On There’s a piece of malware called Stealka that’s been actively spreading since December…
continue reading..
Malicious npm Package “lotusbail” Discovered: WhatsApp Credential Theft and Backdoor Installation
Package Overview Aspect Details Package Name lotusbail Package Registry npm Package Type Malicious Library Masquerade Target WhatsApp…
continue reading..
CVE-2025-68561: AutomatorWP SQL Injection — Database Breach in 60 Seconds
Vulnerability Summary Aspect Details CVE ID CVE-2025-68561 Vulnerability Type SQL Injection (CWE-89) Affected Software AutomatorWP WordPress Plugin…
continue reading..
CVE-2025-13183: Persistent Stored XSS Flaw in Otello Enables Silent User Session Compromise
Vulnerability Summary Detail Information CVE ID CVE-2025-13183 What is it? Stored Cross-Site Scripting (XSS) Where? Otello by…
continue reading..
XRed Malware: A Silent Backdoor Exploiting Tax Compliance Urgency
Executive Summary Between October and December 2025, a targeted malware campaign using the XRed backdoor compromised multiple…
continue reading..
Tycoon Phishing Kit : How Phishing-as-a-Service Defeats Modern MFA
The Tycoon phishing kit is a commercial phishing-as-a-service (PhaaS) framework widely used to steal cloud identity credentials,…
continue reading..
