A government-linked Indian IT portal served a fake Cloudflare check that tried to get visitors to run a copied command.
WordPress ships an emergency fix for a pre-auth XSS chain that ends in PHP code execution.
A pre-auth XSS chain that needs only a crafted username ends in PHP code execution on stock installs.
A poisoned JavaScript file served by ad tech firm Adform rewrote crypto wallet addresses on customer sites.