Apr 01, 2025Ravie LakshmananCryptojacking / Cloud Security
Exposed PostgreSQL instances are the target of an ongoing campaign designed to gain unauthorized access and deploy...
A new sophisticated phishing-as-a-service (PhaaS) platform called Lucid has targeted 169 entities in 88 countries using smishing messages propagated via Apple iMessage and...
A new security issue is putting WordPress-powered websites at risk. Hackers are abusing the “Must-Use” plugins (MU-plugins) feature to hide malicious code and...
Because the attack affected customers, Pavlykevych met right away with their infosec teams, providing ongoing briefs on progress, incident investigation, and recovery “to...
Mar 31, 2025Ravie LakshmananData Theft / Website Security
Threat actors are using the "mu-plugins" directory in WordPress sites to conceal malicious code with the...
The threat actors behind the zero-day exploitation of a recently-patched security vulnerability in Microsoft Windows have been found to deliver two new backdoors...