Malicious Tags Used to Inject Credential Stealer Into Laravel-Lang Packages

Attackers rewrote git tags in Laravel-Lang PHP packages to inject a credential stealing payload that executes silently on application startup.

The Latest

Breaking News and Alerts

Critical LiteSpeed Plugin Flaw Lets Attackers Execute Commands as Root

Attackers are actively exploiting a maximum severity privilege escalation flaw in the LiteSpeed cPanel plugin that grants arbitrary script execution as root.

Spotlight

Cybersecurity Profiles and Stories

Unlocking Hidden Attack Surface: Testing Windows Drivers Without Their Hardware

A new methodology shows how to test Windows kernel driver vulnerabilities for exploitability without requiring the specific hardware the driver was built for.

International Operation Shuts Down VPN Service Used by Two Dozen Ransomware Groups

A VPN service advertised on Russian cybercrime forums as a way to hide from police has been taken offline in a multinational operation across 18 countries.

Anthropic’s Claude Mythos AI Uncovers Thousands of Critical Flaws in Key Software

Anthropic's Claude Mythos Preview AI identified over 10,000 high-severity flaws in critical software, with 97 findings already patched upstream.

Critical Flaw in Nginx Web Server Allows Code Execution Via Heap Overflow

A new heap overflow vulnerability in NGINX allows unauthenticated remote attackers to crash worker processes or execute arbitrary code.

Features

Research and Thought Leadership