Funnel Builder Flaw Enables WooCommerce Skimming
ALERT: Hackers exploit Funnel Builder flaw to inject skimmers into WooCommerce checkouts, stealing payment data. 600K+ sites at risk. Patch NOW. Severity: High Target: WooCommerce sites
ALERT: Hackers exploit Funnel Builder flaw to inject skimmers into WooCommerce checkouts, stealing payment data. 600K+ sites at risk. Patch NOW. Severity: High Target: WooCommerce sites
Critical Funnel Builder plugin flaw actively exploited to inject card-stealing malware into WordPress checkout pages. 400K+ sites at risk. Patch immediately.
CISA adds Microsoft Exchange Server XSS vulnerability to KEV Catalog amid active exploitation. Federal agencies have a deadline—but all orgs should patch now.
Russian state hackers Turla transformed their Kazuar backdoor into a stealthy P2P botnet for persistent access. FSB-linked group ups their game with modular malware.
Hackers weaponize PyInstaller to smuggle XWorm RAT past Windows defenses. AMSI patching lets them steal data and hijack devices undetected.
Gunra ransomware evolved from Conti roots into a full-scale RaaS operation, hitting dozens of orgs globally in under a year with leak sites and affiliate programs
SpaceX’s upgraded Starship launches first test flight May 19. New capabilities could reshape space infrastructure—and expand the attack surface cybersecurity pros must defend.
Hackers are weaponizing Microsoft’s OAuth device flow to steal M365 credentials at scale. This little-known attack vector has exploded since late 2024.
Ghostwriter APT group strikes again: New campaign targeting Ukrainian government organizations uncovered by ESET researchers. FrostyNeighbor continues its attacks.
Hackers now hijacking M365 accounts through Outlook calendar invites. The EvilTokens kit lets attackers steal session tokens and bypass MFA entirely.