GoPhish Login Page Detected - 195[.]22[.]17[.]59:443 - https://www.redpacketsecurity.com/gophish-login-detected-195-22-17-59-port-443/
RedPacket Security
GoPhish Login Page Detected - 195[.]22[.]17[.]59:443 - RedPacket Security
GoPhish Login Page Detection Alerts
GoPhish Login Page Detected - 20[.]172[.]175[.]211:3000 - https://www.redpacketsecurity.com/gophish-login-detected-20-172-175-211-port-3000/
RedPacket Security
GoPhish Login Page Detected - 20[.]172[.]175[.]211:3000 - RedPacket Security
GoPhish Login Page Detection Alerts
GoPhish Login Page Detected - 120[.]55[.]241[.]190:443 - https://www.redpacketsecurity.com/gophish-login-detected-120-55-241-190-port-443/
RedPacket Security
GoPhish Login Page Detected - 120[.]55[.]241[.]190:443 - RedPacket Security
GoPhish Login Page Detection Alerts
GoPhish Login Page Detected - 82[.]165[.]97[.]150:3333 - https://www.redpacketsecurity.com/gophish-login-detected-82-165-97-150-port-3333/
RedPacket Security
GoPhish Login Page Detected - 82[.]165[.]97[.]150:3333 - RedPacket Security
GoPhish Login Page Detection Alerts
[INCRANSOM] - Ransomware Victim: hsc[.]mb[.]ca - https://www.redpacketsecurity.com/incransom-ransomware-victim-hsc-mb-ca/
RedPacket Security
[INCRANSOM] - Ransomware Victim: hsc[.]mb[.]ca - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
Mythic C2 Detected - 185.213.22.64185[.]213[.]22[.]64:7443 - https://www.redpacketsecurity.com/mythic-c2-detected-185-213-22-64-port-7443/
RedPacket Security
Mythic C2 Detected - 185.213.22.64185[.]213[.]22[.]64:7443 - RedPacket Security
Mythic C2 Detection Alerts
[QILIN] - Ransomware Victim: Confipetrol - https://www.redpacketsecurity.com/qilin-ransomware-victim-confipetrol/
RedPacket Security
[QILIN] - Ransomware Victim: Confipetrol - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
Weekly Ransomware Intelligence Report: 4 October 2026 to 11 October 2026 - https://www.redpacketsecurity.com/weekly-ransomware-intelligence-report-2026-10-04-2026-10-11/
RedPacket Security
Weekly Ransomware Intelligence Report: 4 October 2026 to 11 October 2026 - RedPacket Security
Ransomware activity at a glance
[RHYSIDA] - Ransomware Victim: Charles E[.] Tabor AAL LLC - https://www.redpacketsecurity.com/rhysida-ransomware-victim-charles-e-tabor-aal-llc/
RedPacket Security
[RHYSIDA] - Ransomware Victim: Charles E[.] Tabor AAL LLC - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[DRAGONFORCE] - Ransomware Victim: TQC S[.]A[.] - https://www.redpacketsecurity.com/dragonforce-ransomware-victim-tqc-s-a/
RedPacket Security
[DRAGONFORCE] - Ransomware Victim: TQC S[.]A[.] - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-107657 - hivepress - HivePress – Business Directory, Listings & Classified Ads Plugin - https://www.redpacketsecurity.com/cve-alert-cve-2026-107657-hivepress-hivepress-business-directory-listings-classified-ads-plugin/
RedPacket Security
CVE Alert: CVE-2026-107657 - hivepress - HivePress – Business Directory, Listings & Classified Ads Plugin - RedPacket Security
The HivePress – Business Directory, Listings & Classified Ads Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '<custom
CVE Alert: CVE-2026-108161 - fusionpbx - fusionpbx - https://www.redpacketsecurity.com/cve-alert-cve-2026-108161-fusionpbx-fusionpbx/
RedPacket Security
CVE Alert: CVE-2026-108161 - fusionpbx - fusionpbx - RedPacket Security
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute
CVE Alert: CVE-2026-108546 - spotweb - spotweb - https://www.redpacketsecurity.com/cve-alert-cve-2026-108546-spotweb-spotweb/
RedPacket Security
CVE Alert: CVE-2026-108546 - spotweb - spotweb - RedPacket Security
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by
CVE Alert: CVE-2026-108548 - iflytek - astron-rpa - https://www.redpacketsecurity.com/cve-alert-cve-2026-108548-iflytek-astron-rpa/
RedPacket Security
CVE Alert: CVE-2026-108548 - iflytek - astron-rpa - RedPacket Security
AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without
CVE Alert: CVE-2026-91136 - Divi Essential - Divi Plus - https://www.redpacketsecurity.com/cve-alert-cve-2026-91136-divi-essential-divi-plus/
RedPacket Security
CVE Alert: CVE-2026-91136 - Divi Essential - Divi Plus - RedPacket Security
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the
CVE Alert: CVE-2026-108553 - OpenRefine - OpenRefine - https://www.redpacketsecurity.com/cve-alert-cve-2026-108553-openrefine-openrefine/
RedPacket Security
CVE Alert: CVE-2026-108553 - OpenRefine - OpenRefine - RedPacket Security
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet
CVE Alert: CVE-2026-108628 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108628-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108628 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any
CVE Alert: CVE-2026-108549 - chenhg5 - cc-connect - https://www.redpacketsecurity.com/cve-alert-cve-2026-108549-chenhg5-cc-connect/
RedPacket Security
CVE Alert: CVE-2026-108549 - chenhg5 - cc-connect - RedPacket Security
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts
CVE Alert: CVE-2026-108550 - iflytek - skillhub - https://www.redpacketsecurity.com/cve-alert-cve-2026-108550-iflytek-skillhub/
RedPacket Security
CVE Alert: CVE-2026-108550 - iflytek - skillhub - RedPacket Security
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers
CVE Alert: CVE-2026-108623 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108623-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108623 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to
CVE Alert: CVE-2026-108657 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108657-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108657 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to