[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - https://www.redpacketsecurity.com/exitium-ransomware-victim-koike-sanso-kogoyo-co-ltd/
RedPacket Security
[EXITIUM] - Ransomware Victim: KOIKE Sanso Kogoyo Co[.] Ltd[.] - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - https://www.redpacketsecurity.com/qilin-ransomware-victim-secretaria-de-modernizacion-e-innovacion-del-municipio/
RedPacket Security
[QILIN] - Ransomware Victim: Secretaría de Modernización e Innovación del Municipio - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: ACI Proyectos SAS - https://www.redpacketsecurity.com/qilin-ransomware-victim-aci-proyectos-sas/
RedPacket Security
[QILIN] - Ransomware Victim: ACI Proyectos SAS - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-information-disclosure-unauthen-leak-private-content-truong-nguyen-long/
RedPacket Security
HackerOne Bug Bounty Disclosure: information-disclosure-unauthen-leak-private-content-truong-nguyen-long - RedPacket Security
CompanyWordPress
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - https://www.redpacketsecurity.com/cve-alert-cve-2026-100196-wp-media-lazyload-plugin-lazy-load-images-videos-and-iframes/
RedPacket Security
CVE Alert: CVE-2026-100196 - wp_media - LazyLoad Plugin – Lazy Load Images, Videos, and Iframes - RedPacket Security
The LazyLoad Plugin – Lazy Load Images, Videos, and Iframes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment_content
CVE Alert: CVE-2026-96682 - 2winfactor - Presto Player - https://www.redpacketsecurity.com/cve-alert-cve-2026-96682-2winfactor-presto-player/
RedPacket Security
CVE Alert: CVE-2026-96682 - 2winfactor - Presto Player - RedPacket Security
The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via <presto-player> Tag in all versions up to,
CVE Alert: CVE-2026-107742 - 10web - 10Web Booster – Website speed optimization, Cache & Page Speed optimizer - https://www.redpacketsecurity.com/cve-alert-cve-2026-107742-10web-10web-booster-website-speed-optimization-cache-page-speed-optimizer/
RedPacket Security
CVE Alert: CVE-2026-107742 - 10web - 10Web Booster – Website speed optimization, Cache & Page Speed optimizer - RedPacket Security
The 10Web Booster – Website speed optimization, Cache & Page Speed optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the
CVE Alert: CVE-2026-100161 - villatheme - Photo Reviews for WooCommerce - https://www.redpacketsecurity.com/cve-alert-cve-2026-100161-villatheme-photo-reviews-for-woocommerce/
RedPacket Security
CVE Alert: CVE-2026-100161 - villatheme - Photo Reviews for WooCommerce - RedPacket Security
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'wcpr_image_upload_id' parameter in all
CVE Alert: CVE-2026-12626 - ladela - Online Scheduling and Appointment Booking System – Bookly - https://www.redpacketsecurity.com/cve-alert-cve-2026-12626-ladela-online-scheduling-and-appointment-booking-system-bookly/
RedPacket Security
CVE Alert: CVE-2026-12626 - ladela - Online Scheduling and Appointment Booking System – Bookly - RedPacket Security
The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,
CVE Alert: CVE-2026-94538 - JoomUnited - WP File Download - https://www.redpacketsecurity.com/cve-alert-cve-2026-94538-joomunited-wp-file-download/
RedPacket Security
CVE Alert: CVE-2026-94538 - JoomUnited - WP File Download - RedPacket Security
The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not
CVE Alert: CVE-2026-95684 - e4jvikwp - VikBooking Hotel Booking Engine & PMS - https://www.redpacketsecurity.com/cve-alert-cve-2026-95684-e4jvikwp-vikbooking-hotel-booking-engine-pms/
RedPacket Security
CVE Alert: CVE-2026-95684 - e4jvikwp - VikBooking Hotel Booking Engine & PMS - RedPacket Security
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'attachments' Parameter in all versions up
[UMBRA] - Ransomware Victim: Helwan University (HITU) - https://www.redpacketsecurity.com/umbra-ransomware-victim-helwan-university-hitu/
RedPacket Security
[UMBRA] - Ransomware Victim: Helwan University (HITU) - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[REDACT] - Ransomware Victim: DexCom - https://www.redpacketsecurity.com/redact-ransomware-victim-dexcom/
RedPacket Security
[REDACT] - Ransomware Victim: DexCom - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[DRAGONFORCE] - Ransomware Victim: TEXMA International Co[.], Ltd - https://www.redpacketsecurity.com/dragonforce-ransomware-victim-texma-international-co-ltd/
RedPacket Security
[DRAGONFORCE] - Ransomware Victim: TEXMA International Co[.], Ltd - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[MAJINAHANASHI] - Ransomware Victim: HYSYTECH S[.]r[.]l[.] - https://www.redpacketsecurity.com/majinahanashi-ransomware-victim-hysytech-s-r-l/
RedPacket Security
[MAJINAHANASHI] - Ransomware Victim: HYSYTECH S[.]r[.]l[.] - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[THEGENTLEMEN] - Ransomware Victim: Royal Thai Air Force - https://www.redpacketsecurity.com/thegentlemen-ransomware-victim-royal-thai-air-force/
RedPacket Security
[THEGENTLEMEN] - Ransomware Victim: Royal Thai Air Force - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
Sliver C2 Detected - 177[.]3[.]40[.]23:31337 - https://www.redpacketsecurity.com/sliver-c2-detected-177-3-40-23-port-31337/
RedPacket Security
Sliver C2 Detected - 177[.]3[.]40[.]23:31337 - RedPacket Security
Covenant C2 Detection Alerts
Sliver C2 Detected - 194[.]226[.]187[.]161:31337 - https://www.redpacketsecurity.com/sliver-c2-detected-194-226-187-161-port-31337/
RedPacket Security
Sliver C2 Detected - 194[.]226[.]187[.]161:31337 - RedPacket Security
Covenant C2 Detection Alerts
Sliver C2 Detected - 151[.]243[.]24[.]56:31337 - https://www.redpacketsecurity.com/sliver-c2-detected-151-243-24-56-port-31337/
RedPacket Security
Sliver C2 Detected - 151[.]243[.]24[.]56:31337 - RedPacket Security
Covenant C2 Detection Alerts
Sliver C2 Detected - 23[.]238[.]117[.]41:31337 - https://www.redpacketsecurity.com/sliver-c2-detected-23-238-117-41-port-31337/
RedPacket Security
Sliver C2 Detected - 23[.]238[.]117[.]41:31337 - RedPacket Security
Covenant C2 Detection Alerts
Sliver C2 Detected - 89[.]126[.]250[.]93:31337 - https://www.redpacketsecurity.com/sliver-c2-detected-89-126-250-93-port-31337/
RedPacket Security
Sliver C2 Detected - 89[.]126[.]250[.]93:31337 - RedPacket Security
Covenant C2 Detection Alerts