HuluCaptcha: Fake Captcha Kit Tricks Users into Executing Code via Windows Run Command

Security researchers have identified a sophisticated phishing campaign leveraging a fake CAPTCHA verification system dubbed “HuluCaptcha” that covertly executes malicious code through the Windows Run command. The attack chain begins with seemingly legitimate CAPTCHA challenges that, upon interaction, trigger script…

vBulletin Vulnerability Exploited in the Wild

Exploitation of the vBulletin vulnerability tracked as CVE-2025-48827 and CVE-2025-48828 started shortly after disclosure. The post vBulletin Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: vBulletin Vulnerability Exploited…

ASW wird VSW: Strümpfel löst Borgschulze ab

Der ASW Bundesverband firmiert künftig als VSW. Neuer Präsident ist Johannes Strümpfel, der den sicherheitspolitischen Kurs weiter stärken will. Dieser Artikel wurde indexiert von Newsfeed Lesen Sie den originalen Artikel: ASW wird VSW: Strümpfel löst Borgschulze ab

New PyPI Supply Chain Attacks Target Python and NPM Users on Windows and Linux

Checkmarx Zero researcher Ariel Harush has uncovered a sophisticated malicious package campaign targeting Python and NPM users across Windows and Linux platforms through typo-squatting and name-confusion attacks against popular packages. This coordinated supply chain attack demonstrates unprecedented cross-ecosystem tactics and…