ZeroHour

Indicators of compromise

1,946 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use

TypeIndicatorContextArticleFirst seen
domainlightningproxies.net, vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularly where such connections do not align with nHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainstorjshare.io.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]net , particularlyHackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
domainvultrobjects.compected access to api[.]telegram[.]org , backblazeb2[.]com , vultrobjects[.]com , storjshare[.]io , iproyal[.]com and lightningproxies[.]Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
GBHackers
· 1d ago
ipv4104.194.9.1385c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a succesAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4114.10.43.2030 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv4187.75.114.361 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack peAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.137.105.21441.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv423.180.120.140.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 BeAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv431.59.129.150originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv437.114.144.20914 23.180.120.140 104.194.9.138 187.75.114.36 114.10.43.203 37.114.144.209 Because a successful attack permits an attacker to upload aAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv46.17.4.1the plugin, has addressed the flaws in version 6.17.3.1 and 6.17.4.1, respectively. Found this article interesting? Follow us onAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.140dresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.105.214 23.180.120.140 104.194.9.138 187.75.114.36 1Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
ipv492.241.13.213attempts have originated from the following IP addresses - 92.241.13.213 31.59.129.150 2a0f:85c1:840:5389::1 92.241.13.140 23.137.10Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News
· 1d ago
domaingithub.comilable in the following pull requests for community users - github[.]com/wso2/carbon-apimgt/pull/13752 github[.]com/wso2/product-aActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News
· 1d ago
domainbrevo.comn a Brevo-sent campaign email AttackerBrevocode injected in brevo.com & sendibt1.comBrevo customers100k+ sites and mailing listsEBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn10.sendibt1.comom cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware hostBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn11.sendibt1.comm 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1.com # C2 paths, relative to the malware host /f.js the loader /Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn2.sendibt1.comhild (s); })(); These loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domaincdn3.sendibt1.comese loader domains vary: cdn.sendibt1.com cdn2.sendibt1.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com cdn10.sendibt1.com cdn1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendibt1.coms suggests a single Cloudflare account holding all of them, sendibt1.com included. That is the zone where the attacker created the cBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsendinblue.comudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a single Cloudflare accounBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibautomation.comdomains all use Cloudflare DNS: brevo.com , sibforms.com , sibautomation.com , sendinblue.com and sendibt1.com . This suggests a singleBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainsibforms.comrevo.com iframe page that backs the chat widget, and on the sibforms.com pages that serve hosted signup and unsubscribe forms: < scrBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4104.21.77.104sts (all NXDOMAIN since 15 September 2026) cdn.sendibt1.com 104.21.77.104 created 2026-08-25 17:08 UTC cdn2.sendibt1.com cdn3.sendibtBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4172.246.243.65endibt1.com itself is not proxied, answering on Brevo's own 172.246.243.65 in AS200484 with server: envoy , while only the attacker'sBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
ipv4188.114.97.31.com cdn3.sendibt1.com cdn4.sendibt1.com cdn9.sendibt1.com 188.114.97.3 first observed 2026-09-14 cdn10.sendibt1.com cdn11.sendibt1Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha25626166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddcatps://conversations-widget.brevo.com/brevo-conversations.js 26166cd87ff07e7a50317a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e3Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha2564af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7sponse, identical across every host and every observed scan 4af488d79aef7daa12b1c18f0cce28b7edadccb8b6b0fb8d50d1d53a9a7c2df7 {"s":0,"r":"https:\/\/www.google.com"} # Do not block sendiBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha25658a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a43230871db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980Brevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha2569b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a57a24126d14b262e842c5715585636dee3ab3f227ddca clean, 72816 B 9b62c12bc5c7feb9802f58e6cf75a368690df3c754e37cc64483a92acacf87a5 injected -> cdn4 # The appended line (final line of each fiBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha256f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782588fc39f97712d9b878795f6ee500590099a432308 injected -> cdn2 f67d572d2d30407b3f470904326411450763108980cdad89550fbb221fb06782 injected -> cdn11 https://conversations-widget.brevo.com/brBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
sha256fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09e 15 September 2026) https://cdn.brevo.com/js/sdk-loader.js fe8447fd1ec4dca652b71db2c749fcc24a5bec3875f3654042169fb2418aed09 clean, 3442 B 58a5c601c9df7ca2120435588fc39f97712d9b878795fBrevo supply chain attack hits 100k+ sites with Wordpress backdoors and Clickfix malware
Sansec (Magento / e-commerce security)
· 1d ago
domainvip311.cce. Screenshots of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc assLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzenplay77-x.spaceo sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated with PeckBirdy. The problem iLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainzzyud.coms of three casino sites identified by Infoblox—vip311[.]cc, zzyud[.]com and zenplay77-x[.]space—with vip311[.]cc associated withLow-quality casino sites conceal highly dangerous threat actors
The Register · Security
· 1d ago
domainluizestrelhashapr.onlinefiltrating browser data for each profile to its C2 server ("luizestrelhashapr[.]online:443") but not before requesting extensive access to browsKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainvolmira.siteto the same Ethereum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain thKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainzaviro.onlineum smart contract to fetch two domains – volmira[.]site and zaviro[.]online – and queries the former to obtain the browser extensionKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News
· 1d ago
domainc2iznja.comon the machine and exfiltrate them to the C2 server ("api80.c2iznja[.]com"). "The domains used Cloudflare as a proxy for their infrBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
domainchat5188.tkgather system details and transmit them to the C2 server ("chat5188[.]tk"). In response, the server issues commands to load a plugBambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News
· 1d ago
ipv42.0.3.1aw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer
· 1d ago
domainhunt.iomand-and-control (C&C) platform for remote administration,” Hunt.io says. Next, the attackers used various scripts for host disThai Broadband Provider Hacked via Fortinet Vulnerability
SecurityWeek
· 2d ago
domain31-59-175-195.syd.nbn.aussiebb.netgets through redirect and tracking infrastructure including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . ThPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domaineightindigostove.com75-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was assessed as fake renewal scarewPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainloadswage.comture including 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net , loadswage[.]com , and eightindigostove[.]com . The final operation was asPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainmoolaah.comd through Amazon Simple Email Service from the DKIM-aligned moolaah[.]com domain and urged recipients to open a supposed MahnschreiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainopensea.ioitting a concealed POST request and eventually resolving to opensea[.]io during live analysis. Virus Bulletin’s Q3 2026 VBSpam tesPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainweb5-4s4c-online-garantibbva.vibtee.coms IPv4 address 103[.]193[.]179[.]223 and redirected through web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ before ultimately reaching Google during verificatiPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainwebsite-2df62808.mvplineup.coment reminder. No file was attached. Its embedded URL led to website-2df62808[.]mvplineup[.]com/audacity/underside , a first-stage page containing decoPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
domainxmasbrick.com: Virus Bulletin). Sent from the DKIM-aligned but unrelated xmasbrick[.]com domain, the message embedded an IPv6-mapped address: hxxpPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF[.]com domain, the message embedded an IPv6-mapped address: hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 . That notation represents IPv4 address 103[.]193Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers
· 2d ago
ipv4104.194.9.1385389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentioHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv4187.75.114.36.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domains are intentionally defanged (Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv42.0.3.1bility , tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 oHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv423.137.105.2143 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP aHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv423.180.120.1403 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.114.36 Note: IP addresses and domaHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv431.59.129.150e most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blocked requests, foHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv492.241.13.140r 1 92.241.13.213 2 31.59.129.150 3 2a0f:85c1:840:5389::1 4 92.241.13.140 5 23.137.105.214 6 23.180.120.140 7 104.194.9.138 8 187.75.Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
ipv492.241.13.213and August 30. The most active sources reportedly included 92.241.13.213 and 31.59.129.150, each responsible for more than 24,000 blHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers
· 2d ago
domain31-59-175-195.syd.nbn.aussiebb.netof compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renewNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domaineightindigostove.comssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus reneNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainloadswage.comsed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus renNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainmoolaah.compath in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainopensea.ioing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser-New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainweb5-4s4c-online-garantibbva.vibtee.comPv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking pNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainwebsite-2df62808.mvplineup.comomain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in thNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainxmasbrick.comthe cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the RomaNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
urlhttp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DFnder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankinNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News
· 2d ago
domainapi.telegram.orging in logging unexpectedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io ipIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainbackblazeb2.comctedly should be investigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightninIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainiproyal.com[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is foIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainlightningproxies.netzeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The best defence is for the user/victim to beIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainstorjshare.io: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net Mitigations The bestIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainvultrobjects.comnvestigated further: api[.]telegram[.]org backblazeb2[.]com vultrobjects[.]com storjshare[.]io iproyal[.]com lightningproxies[.]net MitiIranian cyber targeting of dissidents, activists and journalists
NCSC UK
· 2d ago
domainember-bridge.comlution with a web protection component. Malwarebytes blocks ember-bridge.com, which is part of the PasteSwitch infrastructure. Educate yHBO Max’s verified Reddit account hijacked to spread malware
Malwarebytes Labs
· 2d ago
ipv4104.194.9.138urce of more than 6,600 blocked exploit requests IP address 104.194.9.138 Observed source of more than 6,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv4114.10.43.203source of more than 470 blocked exploit requests IP address 114.10.43.203 Observed source of more than 310 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv4187.75.114.36urce of more than 6,100 blocked exploit requests IP address 187.75.114.36 Observed source of more than 470 blocked exploit requests IHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv423.137.105.214urce of more than 9,100 blocked exploit requests IP address 23.137.105.214 Observed source of more than 6,700 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv423.180.120.140urce of more than 6,700 blocked exploit requests IP address 23.180.120.140 Observed source of more than 6,600 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv431.59.129.150rce of more than 24,900 blocked exploit requests IP address 31.59.129.150 Observed source of more than 24,000 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv437.114.144.209source of more than 310 blocked exploit requests IP address 37.114.144.209 Observed source of more than 310 blocked exploit requests FHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv492.241.13.140rce of more than 16,000 blocked exploit requests IP address 92.241.13.140 Observed source of more than 9,100 blocked exploit requestsHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
ipv492.241.13.213f compromise (IoCs):- Type Indicator Description IP address 92.241.13.213 Observed source of more than 24,900 blocked exploit requestHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News
· 2d ago
domainserver.hostexposes the Vite dev server to the network using --host or server.host config option The sensitive file exists in the allowed direMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
The Hacker News
· 2d ago
domainclean-disk-guide.comoke down into 15 ads for a fake macOS disk utility at apple.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. OAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domaincode-desktop.com.clean-disk-guide[.]com and 11 for other developer tools at code-desktop[.]com. One entry point into a larger system The HBO Max ads werAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domaincodex-craft.com-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-craft[.]com. The rest broke down into 15 ads for a fake macOS disk utAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domainhbomax-macos.coms, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex, pointing to codex-crafAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domainhbomaxx.appid . Of the 108 ads, 46 used an HBO Max lure, split between hbomaxx[.]app and hbomax-macos[.]com. Another 36 posed as OpenAI Codex,Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domainhbomaxx.usHBO Max subreddits,” wrote the user. Clicking the ad led to hbomaxx[.]us, “which looks somewhat legitimate, and has a join buttonAttackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Help Net Security
· 2d ago
domainhbomaxx.usich does not exist. Clicking the malicious ads led users to hbomaxx[.]us, a page mimicking the official HBO Max site that also conHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
SecurityWeek
· 2d ago
domainbiterflll.comy tips in seconds. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitigift.coms. Indicators of compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitrefall.comf compromise (IOCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitrefill.comed or charged back. Confirm that the main domain is exactly bitrefill.com before approving a payment. Be wary of domains containing aSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitrefill-payments.comCs) Domains: biterflll[.]com bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitrSearch results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitrefill-pays.comcom bitigift[.]com bitrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitregift.comtrefall[.]com bitrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago
domainbitregill.comtrefill-payments[.]com bitrefill-pays[.]com bitregift[.]com bitregill[.]com bitretill[.]com bitrgift[.]com bitrgifts[.]com bitrnfill[Search results are sending people to fake Bitrefill checkouts
Malwarebytes Labs
· 2d ago

Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.