home.social

#codeinjection — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #codeinjection, aggregated by home.social.

fetched live
  1. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  2. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  3. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  4. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  5. Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

    Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.

    Pulse ID: 6a6a0753fc3cdb9a380c795d
    Pulse Link: otx.alienvault.com/pulse/6a6a0
    Pulse Author: AlienVault
    Created: 2026-07-29 13:59:47

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Clipboard #CodeInjection #Cookies #CyberSecurity #Discord #Email #FileZilla #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #Outlook #Password #Passwords #Phishing #PowerShell #RAT #ShellCode #Steganography #Telegram #WinSCP #Word #bot #cryptocurrency #AlienVault

  6. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  7. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  8. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  9. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  10. Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

    On July 14, 2026, a coordinated supply chain attack compromised the @asyncapi npm organization, affecting five package versions across four packages. The attack originated from a GitHub Actions workflow vulnerability that exposed privileged credentials, enabling unauthorized code injection. Unlike typical postinstall attacks, this campaign executes at module import time, bypassing common npm install --ignore-scripts protections. The malicious code spawned hidden processes that fetched a second-stage payload from IPFS, deploying the Miasma modular runtime with command-and-control capabilities, persistence mechanisms, and credential harvesting features. The payload included disabled modules for supply-chain propagation, AI-tool poisoning, and sandbox evasion. All compromised packages were published through legitimate GitHub OIDC workflows with valid provenance signatures, masking the malicious activity within trusted release processes.

    Pulse ID: 6a58813c09a76d1819c69bb0
    Pulse Link: otx.alienvault.com/pulse/6a588
    Pulse Author: AlienVault
    Created: 2026-07-16 06:59:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CredentialHarvesting #CyberSecurity #GitHub #InfoSec #NPM #OTX #OpenThreatExchange #Rust #SMS #SupplyChain #Vulnerability #bot #AlienVault

  11. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  12. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  13. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  14. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  15. #NanoClaw and #JFrog have partnered to launch a #security integration that protects NanoClaw autonomous #agents from malicious #codeinjection. The integration hardwires NanoClaw agents to JFrog’s vetted software registries, ensuring they only download safe dependencies. This addresses the growing risk of autonomous agents installing packages without human oversight, often falling victim to software supply chain attacks. venturebeat.com/security/nanoc #AIagent #AI #ML #NLP #LLM #GenAI

  16. GitHub Breach Exposes 3800 Repositories via Poisoned VS Code Extension

    A malicious Visual Studio Code extension, Nx Console, was briefly listed on official registries and used to breach GitHub, exposing approximately 3,800 internal repositories to unauthorized access. The popular extension, with 2.2 million installs, was compromised for just 18 minutes, but long enough to cause significant damage.

    osintsights.com/github-breach-

    #Github #VsCode #SupplyChain #CodeInjection #ExtensionVulnerability

  17. SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

    SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

    osintsights.com/sap-patches-cr

    #SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity

  18. GitHub swiftly patches flaw exposing millions of private repos

    GitHub quickly squashed a massive security flaw, CVE-2026-3854, that could have let hackers access millions of private repositories with just one sneaky git push. The vulnerability allowed attackers to inject malicious code by exploiting how GitHub handled user-supplied options during git push operations.

    osintsights.com/github-swiftly

    #Github #Cve20263854 #SupplyChain #CodeInjection #EmergingThreats

  19. Apache ActiveMQ Vulnerability Exploited, Hits 6,400 Servers

    More than 6,400 publicly accessible Apache ActiveMQ servers are under attack, thanks to a high-severity code injection vulnerability that's being actively exploited. Is your server among them?

    osintsights.com/apache-activem

    #ApacheActivemq #CodeInjection #VulnerabilityExploitation #EmergingThreats #ServerSecurity

  20. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  21. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  22. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  23. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  24. 🖥️ Ah yes, the delightful pastime of injecting code into #macOS for absolutely no gain whatsoever! 💸 The author, who simply cannot stop talking about his unrelated love for a Windows tool, generously shares a step-by-step guide on achieving... well, nothing relevant. 🎯 Spoiler: it's all #fun and games until your Mac says "Goodnight, and good luck!" 🌙
    mariozechner.at/posts/2024-07- #coding #codeinjection #techhumor #softwaredevelopment #HackerNews #ngated

  25. 🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! radar.offseq.com/threat/cve-20 #OffSeq #n8n #CodeInjection #Infosec

  26. 🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! radar.offseq.com/threat/cve-20 #OffSeq #n8n #CodeInjection #Infosec

  27. 🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! radar.offseq.com/threat/cve-20 #OffSeq #n8n #CodeInjection #Infosec

  28. 🚨 CVE-2026-27497 (CRITICAL, CVSS 9.4): n8n-io n8n code injection via Merge node's SQL query mode. Authenticated users can achieve RCE and write files. Upgrade to v2.10.1/2.9.3/1.123.22 now! radar.offseq.com/threat/cve-20 #OffSeq #n8n #CodeInjection #Infosec

  29. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  30. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  31. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  32. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  33. W jaki sposób exploit typu Content Injection może zniszczyć społeczność kultowej gry RTS?

    StarCraft: Brood War i jego następca StarCraft 2 to ikony gatunku RTS (strategii czasu rzeczywistego) oraz jedne z najważniejszych gier komputerowych w historii, które od dekad cieszą się aktywną społecznością i profesjonalną sceną e-sportową. Jednak StarCraft 2 stoi obecnie przed poważnymi problemami, które zagrażają jego dalszemu rozwojowi i funkcjonowaniu gry....

    #WBiegu #Blizzard #CodeInjection #Haktywizm #Starcraft

    sekurak.pl/w-jaki-sposob-explo

  34. 🚨 CVE-2025-54444 (CRITICAL): Samsung MagicINFO 9 Server <21.1080.0 lets attackers upload malicious files for remote code execution—no patch yet. Segment servers, restrict uploads, and monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Samsung #CodeInjection #Cybersecurity

  35. 🚨 CVE-2025-54444 (CRITICAL): Samsung MagicINFO 9 Server <21.1080.0 lets attackers upload malicious files for remote code execution—no patch yet. Segment servers, restrict uploads, and monitor closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Samsung #CodeInjection #Cybersecurity

  36. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  37. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  38. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  39. 🚨 ALERT 🚨: Someone figured out that your precious #Dependabot can be manipulated like a sneaky teenager with an unlimited credit card! 🤦‍♂️ Congratulations, now bots can help hackers throw a party in your codebase complete with command injection fireworks. 🎉 Keep pretending your #AppSec is secure, it'll be fun!
    boostsecurity.io/blog/weaponiz #Vulnerability #CodeInjection #SecurityAlerts #HackerNews #HackerNews #ngated

  40. Loki: a new private agent for the popular Mythic framework

    Kaspersky researchers discovered a previously unknown Loki backdoor, utilized in a series of targeted attacks. Analysis revealed that Loki is a private version of an agent compatible with the open-source Mythic framework. The malware employs techniques like memory encryption, indirect system API calls, and API function hashing to impede analysis. It comprises a loader and a DLL, with the latter implementing core functionalities. The loader gathers system information and communicates with the command-and-control server to obtain the payload DLL. Loki inherits commands from various Mythic agents and supports capabilities like file transfers, code injection, and token management. Attackers likely distribute the malware via email, targeting Russian companies across multiple industries.

    Pulse ID: 66debe70d7b21b32deaa1e09
    Pulse Link: otx.alienvault.com/pulse/66deb
    Pulse Author: AlienVault
    Created: 2024-09-09 09:22:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CodeInjection #CyberSecurity #Email #Encryption #InfoSec #Kaspersky #Malware #Mythic #OTX #OpenThreatExchange #RCE #Russia #bot #AlienVault

  41. Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant

    A variant of WikiLoader loader for rent, also known as WailingCrab, is being delivered via SEO poisoning and spoofing of GlobalProtect VPN software. The campaign primarily affects U.S. higher education and transportation sectors. The infection chain involves multiple stages, including DLL sideloading, shellcode injection, and the use of MQTT for command and control. The attackers employ various evasion techniques, such as fake error messages, process checking, and encryption. The loader demonstrates sophisticated tradecraft, including the use of compromised WordPress sites and cloud-based Git repositories for infrastructure.

    Pulse ID: 66d626396c9854978e7a8fb9
    Pulse Link: otx.alienvault.com/pulse/66d62
    Pulse Author: AlienVault
    Created: 2024-09-02 20:55:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CodeInjection #CyberSecurity #Education #Encryption #InfoSec #MQTT #OTX #OpenThreatExchange #RAT #RDP #SEOPoisoning #ShellCode #SideLoading #VPN #WailingCrab #WikiLoader #Word #Wordpress #bot #AlienVault

  42. Hidden Bytecode Injection Techniques Threaten Interpreter Security

    Pulse ID: 66b02cb33cb4d2e1fd1d20c4
    Pulse Link: otx.alienvault.com/pulse/66b02
    Pulse Author: cryptocti
    Created: 2024-08-05 01:36:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CodeInjection #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #cryptocti

  43. 💉 #commandinjection is a type of #cyberattack that involves injecting malicious commands into a system through vulnerable input fields.

    🔒🛡️ Protecting against it is crucial to prevent unauthorized access, #databreaches, and potential system compromise.

    To learn more: bit.ly/45VGBah

    #commandinjectionattack #codeinjection #injectionattacks #owasp #applicationsecurity #vulnerabilities #waap #waf #apptrana #indusface