BGP hijack exposes Softaculous' missing update checks
A 33-hour BGP hijack hit Softaculous, serving malware via Virtualizor updates and prompting credential resets.
30 results for “hijack”
A 33-hour BGP hijack hit Softaculous, serving malware via Virtualizor updates and prompting credential resets.
Anthropic warns that infostealer malware is stealing Claude login sessions to drain accounts.
Researchers found 120 unregistered domains in AI documentation that could be hijacked to infect corporate networks.
Researchers show Anthropic's Claude Code can be tricked into running malicious code by summarizing a website.
Forcepoint shows invisible text can silently change what an AI assistant reads in your email.
A single website visit can hijack NemoClaw's local Ollama model server via DNS rebinding, according to new research.
A NemoClaw weakness lets a webpage hijack local Ollama and inject persistent instructions into models.
Mirage2FA campaign hit 4,532 companies, bypassing MFA and stealing sessions.
Supply-chain attack on Android car head units turns them into proxy nodes and ad fraud tools.
ToxicPanda 2.0 uses VPN permissions to block Google Play, adding 167 commands and targeting 349 apps.
New macOS infostealer AmnesiaStealer combines credential theft with silent remote browser control, researchers report.
A new Mirai-based Linux botnet uses encrypted C2, SOCKS proxies, and exploits in routers to hijack edge devices.
Hundreds of malicious Chrome extensions impersonate VPNs, routing user traffic through a proxy.
Dell has issued an urgent update for its Virtual Storage Integrator to fix a critical vulnerability that allows unauthenticated attackers to hijack sessions.
Researchers identified a post-exploitation toolkit concealed within Oracle database schema objects to bypass endpoint security tools.
Phishing service Greatness uses spoofed RingCentral emails to bypass MFA and compromise Microsoft 365 accounts.
A missing authentication vulnerability in Krayin CRM version 2.2.4 allows remote attackers to hijack the administrator account and gain full system access.
Google's upcoming update aims to stop malware from using enterprise policy keys to seize control of user browser settings.
Threat actors are hijacking hotel network gateways to push fraudulent software updates and capture user credentials via deceptive portals.
Security concerns over hijacked packages have forced a temporary freeze on adopting AUR contributions to protect the ecosystem.
A severe authorization flaw in the better-auth SCIM plugin allows attackers to hijack user accounts and sessions by manipulating provider ID namespaces.
A stored cross-site scripting vulnerability in OpenClaw Dashboard v3.0.0 allows unauthenticated attackers to hijack administrator sessions.
A missing authentication vulnerability in the AMMOS Instrument Toolkit GUI allows unauthenticated attackers to hijack sessions and issue spacecraft commands.
North Korean threat actors are leveraging AI-driven lures and Telegram account hijacks to target cryptocurrency and finance professionals.
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
A flaw in the Pheditor forced password-change flow allows unauthenticated attackers to hijack administrative accounts on systems using default credentials.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
Researchers report that compromised hotel network gateways are redirecting business travelers to sophisticated phishing portals.
Intelligence agencies report that Russian actors are hijacking IP cameras to monitor military movements across Europe and Ukraine.