CVE-2026-1803
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials.
A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials.
CVE-2026-24954
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.
Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.
CVE-2025-65875
An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-70841
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file.
Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file.
CVE-2026-24665
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated.
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated.
SolarWinds Web Help Desk flaw added to CISA KEV
• CVE-2025-40551 (CVSS 9.8): unauthenticated RCE via deserialization
• Fixed in WHD v2026.1
• Federal agencies must patch by February 6
• CVE-2025-40551 (CVSS 9.8): unauthenticated RCE via deserialization
• Fixed in WHD v2026.1
• Federal agencies must patch by February 6
Hackers are delivering AsyncRAT via IPFS-hosted VHD files in DEAD#VAX.
Phishing emails mount fake PDF drives that run obfuscated scripts and in-memory shellcode inside trusted Windows processes—minimal disk trace.
Fileless
IPFS
Process injection
Phishing emails mount fake PDF drives that run obfuscated scripts and in-memory shellcode inside trusted Windows processes—minimal disk trace.
Fileless
IPFS
Process injection
Microsoft built a scanner to detect backdoors in open-weight LLMs 🧠 using 3 behavioral signals.
It flags trigger attention spikes, memorized poisoning data leaks, and fuzzy trigger activation—no retraining required. Built to scan open models at scale.
It flags trigger attention spikes, memorized poisoning data leaks, and fuzzy trigger activation—no retraining required. Built to scan open models at scale.
China-linked Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem.
Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth.
🕸️ Exposed C2 server showed a complete BYOB botnet in the open 🧠
Droppers, loaders, and RATs for Windows, Linux, and macOS were publicly accessible, revealing a multi-stage chain for evasion, persistence, and control. Crypto miners were also hosted.
Droppers, loaders, and RATs for Windows, Linux, and macOS were publicly accessible, revealing a multi-stage chain for evasion, persistence, and control. Crypto miners were also hosted.
eScan antivirus delivered a malicious update after its update system was compromised.
During a two-hour window, attackers swapped a trusted file to stop updates and 🛠️ cleanup. The malware hid by faking update status and downloading more payloads.
During a two-hour window, attackers swapped a trusted file to stop updates and 🛠️ cleanup. The malware hid by faking update status and downloading more payloads.
A high-severity RCE flaw in OpenClaw lets attackers take over the local agent with a single click.
A crafted link can steal a gateway token via unvalidated WebSocket origins, enabling full command execution even on localhost-only setups through the user’s browser.
A crafted link can steal a gateway token via unvalidated WebSocket origins, enabling full command execution even on localhost-only setups through the user’s browser.
Researchers detect active exploitation of a critical React Native CLI flaw.
CVE-2025-11953 allows unauthenticated OS command execution on exposed Metro dev servers, with attacks deploying PowerShell and a Rust payload.
CVE-2025-11953 allows unauthenticated OS command execution on exposed Metro dev servers, with attacks deploying PowerShell and a Rust payload.
Experts at CTM360 report brand impersonation has become a scaled fraud operation.
Its findings show 30,000+ fake fashion stores across 80+ countries, using ads and real payment flows before disappearing.
Its findings show 30,000+ fake fashion stores across 80+ countries, using ads and real payment flows before disappearing.
China-linked Lotus Blossom compromised Notepad++ hosting infrastructure to hijack update traffic and deliver the Chrysalis backdoor, Rapid7 reports.
The average cost to mine a single Bitcoin is now over $90,000. The price of Bitcoin has collapsed to $67,000. Everyone mining Bitcoin at the moment is losing a fortune.
👍3
خطأ بشري في بورصة كورية: موظف Bithumb حول المستخدمين إلى مليونيرات في لحظة
تسبب موظف مبتدئ في بورصة العملات الرقمية الكورية Bithumb عن طريق الخطأ في حالة من الفوضى غير المألوفة، بعد أن نقل 2000 بيتكوين لمئات المستخدمين بدلاً من مكافأة ضئيلة بقيمة 2000 وون كوري (حوالي 1.5 دولار). وفقًا لتقرير في The Korea Times، حدث الخطأ بسبب إدخال وحدة الدفع كـ BTC بدلاً من KRW. ونتيجة لذلك، أصبح العديد من المستخدمين مليونيرات في لحظة وسارعوا إلى بيع البيتكوين الذي حصلوا عليه، مما تسبب في موجة مبيعات مفاجئة وذعر داخل البورصة.
تسبب موظف مبتدئ في بورصة العملات الرقمية الكورية Bithumb عن طريق الخطأ في حالة من الفوضى غير المألوفة، بعد أن نقل 2000 بيتكوين لمئات المستخدمين بدلاً من مكافأة ضئيلة بقيمة 2000 وون كوري (حوالي 1.5 دولار). وفقًا لتقرير في The Korea Times، حدث الخطأ بسبب إدخال وحدة الدفع كـ BTC بدلاً من KRW. ونتيجة لذلك، أصبح العديد من المستخدمين مليونيرات في لحظة وسارعوا إلى بيع البيتكوين الذي حصلوا عليه، مما تسبب في موجة مبيعات مفاجئة وذعر داخل البورصة.
Spain's Deputy Prime Minister Yolanda Díaz:
"I have left X. That network is a place of hate.
We are not vassals of Elon Musk or Trump."
"I have left X. That network is a place of hate.
We are not vassals of Elon Musk or Trump."
Researchers find 341 malicious ClawHub skills targeting OpenClaw users via fake install steps.
The skills deploy Atomic Stealer on macOS and keylogging malware on Windows, abusing OpenClaw’s open marketplace model.
The skills deploy Atomic Stealer on macOS and keylogging malware on Windows, abusing OpenClaw’s open marketplace model.
A supply chain attack spread malware via trusted VS Code extensions on Open VSX.
Attackers hijacked a real developer account and pushed GlassWorm through four existing tools.
22,000+ installs happened before removal.
Attackers hijacked a real developer account and pushed GlassWorm through four existing tools.
22,000+ installs happened before removal.