Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.
Tag: EN
2026-09-24: Files for an ISC Diary (Macfinger ClickFix activity)
This post has no text preview — click the link below to read the original article. This article has been indexed from Malware-Traffic-Analysis.net – Blog Entries Read the original article: 2026-09-24: Files for an ISC Diary (Macfinger ClickFix activity)
Anthropic Releases Lower-Cost Opus 5.5 Ahead Of IPO
AI start-up Anthropic says latest Opus release cuts costs, compute requirements while achieving Fable-like performance
Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline
Crypto casino Duelbits has confirmed a cybersecurity breach that drained approximately $7 million from its hot wallets. In response, the company has taken…
A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
Introduction
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and…
Bitget Confirms $351.6 Million Hot Wallet Hack, Suspends Withdrawals
Crypto exchange Bitget has confirmed unauthorized transfers from part of its hot wallet infrastructure, resulting in estimated losses of about $351.6…
Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the…
Attackers Drain Payy Network After Exploiting Ethereum Bridge Contract
Payy Network has confirmed that an attacker exploited its Ethereum bridge contract and drained its entire balance. As a result, the network and wallet…
Stop watching what AI agents say and start watching what they do
In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot…
OnePlus Android Devices Face Root Access Risk From Unpatched Flaws
Unpatched vulnerabilities in OnePlus software can allow a malicious Android application to gain root-level control of affected devices without requesting…
Cloudflare Containers Flaw Could Expose Data From Other Customers’ Workloads
Cloudflare has addressed a cross-tenant data exposure vulnerability in its Containers platform that could have allowed one customer’s workload to recover…
Half of threat hunters say bad data is their biggest problem
Half of security professionals name data quality or quantity as their biggest barrier to effective threat hunting, according to the SANS 2026 Threat…
Bitget Hot Wallet Hacked – Attackers Stole $351.6 Million From Hot Wallets
Cryptocurrency exchange Bitget has confirmed a security breach affecting approximately $351.6 million in assets after unauthorized transfers were detected…
Your incident count is missing a few incidents
If you run security for a brand with hundreds or thousands of locations, the tools you’ve bought may have little to do with whether an attack stays at one…
Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads
Cloudflare has patched a cross-tenant data exposure vulnerability in its Containers platform across its global, multi-tenant cloud computing…
New infosec products of the month: September 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Akuity, Bitsight, BugBase, Cloud Range, Cohesity,…
ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110,…
Open AI Agents Attack Australian Healthcare
AI Agents Hacking Governments, ShinyHunters Targets FBI, and Muse Zero-Day on Mac | Cybersecurity Today David Shipley covers multiple cybersecurity…
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in…
