Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution
A critical vulnerability chain in the popular Avada WordPress theme allows unauthenticated attackers to execute arbitrary PHP code on servers without user interaction.
CISA Warns of Critical Gitea Vulnerability Exploited in Code Injection Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that attackers are actively exploiting a critical code injection flaw in the Gitea self-hosted Git service.
NovaCookies Phishing Toolkit Exploits DocuSign to Hijack Microsoft 365 Sessions
Researchers have identified a new AitM phishing toolkit called NovaCookies that uses legitimate DocuSign notifications to steal Microsoft 365 authentication sessions.
New Phishing Platform Uses AI Voice Agents to Unlock Stolen iPhones
Researchers have identified a phishing platform called AnonyMousKIT that uses AI-generated voice calls to trick theft victims into revealing their Apple passcodes and 2FA credentials.
New SLEEPWALKER Backdoor Uses Custom Bytecode to Evade Detection
Researchers have discovered a stealthy Windows backdoor called SLEEPWALKER that remains dormant until triggered by a specific network packet to execute custom bytecode.