🔒 Cybersecurity News Feed

Najnowsze informacje z obszaru cybersecurity

Funnel Builder WordPress plugin bug exploited to steal credit cards

📅 2026-05-15 19:30🌐 www.bleepingcomputer.com
A critical vulnerability in the Funnel Builder plugin for WordPress is being actively exploited to inject malicious JavaScript snippets into WooCommerce checkout pages. [...]...
Cybersecurity

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

📅 2026-05-15 17:47🌐 www.bleepingcomputer.com
​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft...
Cybersecurity

Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access

📅 2026-05-15 17:10🌐 feeds.feedburner.com
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent ac...
Cybersecurity

Popular node-ipc npm package compromised to steal credentials

📅 2026-05-15 17:10🌐 www.bleepingcomputer.com
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. [...]...
Cybersecurity

Avada Builder WordPress plugin flaws allow site credential theft

📅 2026-05-15 15:56🌐 www.bleepingcomputer.com
Two vulnerabilities in the Avada Builder plugin for WordPress, with an estimated one million active installations, allow hackers to read arbitrary files and extract sensitive information from the data...
Cybersecurity

Microsoft backpedals: Edge to stop loading passwords into memory

📅 2026-05-15 14:49🌐 www.bleepingcomputer.com
Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was "by design." [...]...
Cybersecurity

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

📅 2026-05-15 13:35🌐 feeds.feedburner.com
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectiv...
Cybersecurity

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

📅 2026-05-15 11:00🌐 feeds.feedburner.com
In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks l...
Cybersecurity

TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates

📅 2026-05-15 10:54🌐 feeds.feedburner.com
OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production system...
Cybersecurity

Atak supply chain na OpenAI. Dwóch developerów zostało zainfekowanych podmienioną przez hackerów biblioteką TanStack (npm)

📅 2026-05-15 10:40🌐 feeds.feedburner.com
Jeśli ktoś chce szybko nadrobić zaległości w temacie ostatnich ataków supply chain, to polecam spojrzeć tutaj (Axios), tutaj (Shai-Hulud), tutaj (Bitwarden Cli) czy tutaj (Mini Shai-Hulud &#821...
Cybersecurity