GhostAction Returns, Hits 340+ Maintainer Repos
A credential-theft campaign has compromised two open-source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories.
30 results for “attack”
A credential-theft campaign has compromised two open-source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories.
Researchers say a single chat prompt could extract cloud credentials and let an attacker take over every AgentCore agent in an AWS account and region.
Attackers are chaining two unpatched AhsayCBS vulnerabilities to gain remote code execution and deploy webshells, with at least five organizations targeted.
The FBI has seized seven domains linked to Chinese state-sponsored hackers, disrupting two key platforms used in attacks on critical infrastructure.
IDC Frontier says a ransomware attack on its IDCF Cloud disrupted East Japan Region 1 and locked 495 companies and local governments out of management consoles.
Attackers reportedly seized control of top-level domains to issue valid-looking TLS certificates for Google and other organizations.
SonicWall issued hotfixes for a maximum-severity SSRF bug in SMA1000 appliances, urging customers to upgrade before attackers take note.
Chip testing firm Advantest says attackers took names, SSNs, and financial data in a February ransomware intrusion.
A phishing email led to the theft of personal data for 1.3 million people from Arizona's court system, officials say.
Attackers seized three country-code domains to mint counterfeit TLS certificates for Google and other brands, Google says.
Nikkei says attackers hit a Google Workspace account in July and a Microsoft 365 account in September, later sending 9,000 phishing emails.
Dell has patched 18 CVEs in its storage and update tools, including two maximum-severity flaws with no workarounds.
Attackers are exploiting CVE-2026-61500 in Rejetto HFS to bypass authentication and gain remote code execution, according to VulnCheck.
Citrix rushed out emergency updates for a SAML authentication flaw already exploited in attacks, but administrators may need to patch twice.
Edtech vendor Frontline Education says attackers exploited a third-party software flaw to access employee data including Social Security numbers.
A 16-year-old led a ransomware crew that claimed about 1,000 attacks, according to European police.
Dutch bug-hunting nonprofit says AI agents exploited Zammad zero-days, stealing researcher emails in seconds.
Microsoft's 2026 Digital Defense Report finds attackers are gaining AI advantages faster than defenders, risking a spike in unpatched vulnerabilities.
A critical authentication bypass in Cisco Catalyst SD-WAN Manager let attackers reach an admin API, and the fix requires an upgrade.
Ofqual survey finds secondary schools reporting fewer incidents and quicker recovery, but training and responsibility gaps persist.
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
PwC's survey of 3934 leaders across 71 countries finds adversarial AI attacks top the list of cybersecurity gaps.
LevelBlue says attackers exploited a critical NetScaler bug to plant web shells, create superuser accounts, and exfiltrate configuration data.
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.
Microsoft says phishing emails hid a legitimate MSP360 installer behind meeting and PDF lures, then used it to install ScreenConnect as a redundant remote-access channel.
Huntress found attackers using custom GPTs and Google Sites to deliver a ClickFix RAT called @input, impacting dozens of users.
F5 patched a critical BIG-IP APM zero-day exploited in remote code execution attacks, as CISA ordered federal agencies to secure networks by Friday.
ESET's 2026 SMB Cyber Risk Report finds 49% of UK small businesses hit by incidents, with AI-powered attacks adding pressure despite core tactics staying the same.
Attackers exploited a management server flaw in July while a separate VPN bug now draws ongoing attempts against small-business firewalls.
Attackers used a compromised credential from the Ribon app to pull customer data from hundreds of online stores, exposing a soft spot in e-commerce supply chains.