Mimo Hackers Exploit CVE-2025-32432 in Craft CMS to Deploy Cryptominer and ProxywareThe Hacker News·Jun 2, 10:07 UTC · Jun 2, 2025VulnerabilityCVE-2025-32432CVE-2021-44228CVE-2022-26134+1 CVEs47
Unmasking the new persistent attacks on JapanCisco Talos·Mar 6, 11:00 UTC · Mar 6, 2025VulnerabilityCVE-2024-4577160
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsThe Hacker News·Apr 6, 06:40 UTC · Apr 6, 2026Vulnerability142
Attackers chained Craft CMS zeroSecurity Affairs·Apr 28, 08:35 UTC · Apr 28, 2025VulnerabilityCVE-2025-32432CVE-2024-5813647
PolyShell: unrestricted file upload in Magento and Adobe CommerceSansec (Magento / e-commerce security)·May 12, 10:55 UTC · May 12, 2026Vulnerability in the wild60
Mass PolyShell attack wave hits 471 stores in one hourSansec (Magento / e-commerce security)·Mar 31, 07:45 UTC · Mar 31, 2026Vulnerability in the wildCVE-2026-7565060
“Keeper” Magecart Group Infects 570 SitesRecorded Future·Jun 27, 00:00 UTC · Jun 27, 2025Vulnerability30
Ghost CMS flaw abused to push ClickFix attacks on hundreds of sitesSecurity Affairs·May 25, 18:07 UTC · May 25, 2026Vulnerability in the wildCVE-2026-2698060
PHP-CGI RCE Flaw Exploited in Attacks on Japan's Tech, Telecom, and EThe Hacker News·Mar 7, 05:42 UTC · Mar 7, 2025VulnerabilityCVE-2024-457747
China-Nexus TAG-112 Compromises Tibetan Websites to Distribute Cobalt StrikeRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Vulnerability42
New Vulnerability in Popular WordPress Plugin Exposes Over 2 Million Sites to CyberattacksThe Hacker News·May 15, 00:00 UTC · May 15, 2023Vulnerability in the wildCVE-2023-30777CVE-2023-30177CVE-2023-31144+1 CVEs60
CVE-2019-6342 flaw allows hackers to compromise Drupal 8.7.4 websitesSecurity Affairs·Jul 18, 09:34 UTC · Jul 18, 2019VulnerabilityCVE-2019-6342CVE-2019-634060
Magecart Group 8 skimmed card info from 570+ online shopsHelp Net Security·Jul 8, 00:00 UTC · Jul 8, 2020Vulnerability42
CVE-2018-7602 - Drupal addressed a new vulnerability associated with Drupalgeddon2 flawSecurity Affairs·Apr 26, 12:49 UTC · Apr 26, 2018Vulnerability in the wildCVE-2018-7602CVE-2018-7600CVE-2017-1027160
Vulnerability Spotlight: XSS vulnerability in Ghost CMSCisco Talos·Jan 19, 20:01 UTC · Jan 19, 2023Vulnerability in the wildCVE-2022-47194CVE-2022-4719760
China-linked group hacked Tibetan media and university sites to distribute Cobalt Strike payloadThe Record·Nov 13, 03:38 UTC · Nov 13, 2024Vulnerability30
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix AttacksThe Hacker News·Jun 26, 07:33 UTC · Jun 26, 2026VulnerabilityCVE-2026-2698060
New WordPress Flaw Lets Unauthenticated Remote Attackers Hack SitesThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2019Vulnerability55
Hackers Have Started Exploiting Drupal RCE Exploit Released YesterdayThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2018VulnerabilityCVE-2018-760060
Researchers Detail Severe "Super FabriXss" Vulnerability in Microsoft Azure SFXThe Hacker News·Mar 30, 17:02 UTC · Mar 30, 2023VulnerabilityCVE-2023-23383CVE-2022-3582960
OpenSSL Releases Patch For "High" Severity VulnerabilityThe Hacker News·Nov 10, 18:03 UTC · Nov 10, 2016VulnerabilityCVE-2016-7054CVE-2016-7053CVE-2016-705535
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60
CMS Provider Sitecore Patches Exploited Critical Zero DayInfosecurity Magazine·Sep 4, 13:30 UTC · Sep 4, 2025VulnerabilityCVE-2025-5369060
Critical auth bypass issues affect InfiniteWP Client and WP Time Capsule WordPress pluginsSecurity Affairs·Jan 16, 08:14 UTC · Jan 16, 2020Vulnerability55
Kaspersky report on APT trends in Q3 2024Kaspersky Securelist·Nov 28, 10:00 UTC · Nov 28, 2024Vulnerability42
100+ Online Shops Compromised With Payment Data-Stealing CodeHelp Net Security·Nov 13, 10:44 UTC · Nov 13, 2024Vulnerability30
Ongoing Xurum attacks target Magento 2 eSecurity Affairs·Aug 14, 17:46 UTC · Aug 14, 2023VulnerabilityCVE-2022-24086CVE-2016-519547
Kazakhstan-associated YoroTrooper disguises origin of attacks as AzerbaijanCisco Talos·Oct 25, 12:01 UTC · Oct 25, 2023Vulnerability30
EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS VulnerabilitiesThe Hacker News·May 31, 04:11 UTC · May 31, 2022VulnerabilityCVE-2022-22954CVE-2022-1388CVE-2022-22947+5 CVEs47
Hackers Exploiting Drupal Vulnerability to Inject Cryptocurrency MinersThe Hacker News·Apr 18, 09:50 UTC · Apr 18, 2018Vulnerability in the wildCVE-2018-7600CVE-2017-1027160
Microsoft Fixes New Azure AD Vulnerability Impacting Bing Search and Major AppsThe Hacker News·Apr 5, 07:20 UTC · Apr 5, 2023Vulnerability in the wildCVE-2023-2338360
Digital skimmer hits global supermarket chainSansec (Magento / e-commerce security)·Apr 14, 20:16 UTC · Apr 14, 2026Vulnerability in the wild57
WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site BackdoorsThe Hacker News·Apr 28, 08:06 UTC · Apr 28, 2025Vulnerability55
CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek DevicesThe Hacker News·Mar 29, 03:45 UTC · Mar 29, 2025Vulnerability in the wildCVE-2019-9874CVE-2019-9875CVE-2020-8515+2 CVEs60
Balada Injector continues to infect thousands of WordPress sitesSecurity Affairs·Jan 15, 10:11 UTC · Jan 15, 2024VulnerabilityCVE-2023-600047
High-Severity Vulnerability Discovered in Popular CMSInfosecurity Magazine·Sep 6, 11:30 UTC · Sep 6, 2023Vulnerability in the wildCVE-2023-2453CVE-2023-448060
SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025Sansec (Magento / e-commerce security)·Apr 14, 19:49 UTC · Apr 14, 2026Vulnerability in the wildCVE-2025-54236260
DarkMoon: Open-source AI pentesting platformHelp Net Security·Jun 29, 00:00 UTC · Jun 29, 2026Vulnerability30