;
;

Security Affairs

Read, think, share … Security is everyone's responsibility

PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory

PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technic...
Posted on 9 September 2026 | 8:50 am

Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Ecl...
Posted on 9 September 2026 | 7:53 am

Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs

September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email...
Posted on 9 September 2026 | 7:03 am

Hackers Drain $320 Million From Liquid Network, Then Return Most of It

Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a rans...
Posted on 8 September 2026 | 8:35 pm

WeChat Worm Can Hijack Accounts Without Victims Answering Calls

Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif crea...
Posted on 8 September 2026 | 6:09 pm

Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data

An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found a...
Posted on 8 September 2026 | 11:01 am

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. No...
Posted on 8 September 2026 | 9:11 am

IT Help Desk Impersonation Lets Hackers Bypass MFA

Attackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget insta...
Posted on 8 September 2026 | 7:41 am

Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak

Condé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to con...
Posted on 7 September 2026 | 7:40 pm

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

StyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may alre...
Posted on 7 September 2026 | 5:49 pm