Risk
-
Hackers exploit critical Everest Forms Pro flaw to seize WordPress sites
Hackers are exploiting a critical flaw in Everest Forms Pro to take over WordPress sites. Wordfence said more than 29,300 attack attempts were blocked after the March patch, and some attacks created rogue administrator accounts.
-
Suspicious Polyfill login prompts appear on Toshiba and Muji sites
Toshiba and Muji warned that suspicious sign-in screens appeared on parts of their websites in Japan this week, with the prompts tied to polyfill.io. The companies said users who entered credentials should change passwords.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
New Android spyware campaign targets Arabic-speaking users, ESET says
ESET says a new Android spyware campaign called Asin used fake utility, news and war map sites to target Arabic-speaking users. The operation remains unattributed, and its main objective has not been confirmed.
-
Researchers link new OP-512 cluster to IIS server espionage campaign
Researchers found a new China-linked threat cluster, OP-512, targeting Microsoft IIS servers with a custom web shell framework. The activity used timestomping, self-reporting shells and attempted privilege escalation on a legacy Windows Server 2016 host.
-
WFP says breach exposed data of about 600,000 Gaza households
The World Food Programme said a breach of its Gaza self-registration system exposed personal details of about 600,000 households. The agency suspended the platform, but said aid delivery and existing registrations would continue.
-
DentaQuest says breach affected part of network, leak tied to 2.6 million accounts
DentaQuest said a security incident exposed data tied to 2.6 million accounts after a breach linked to ShinyHunters. The leaked records included names, contact details, government IDs and health insurance information.
-
China-linked TA4922 widens phishing attacks to Europe and South Africa
China-linked TA4922 has expanded phishing campaigns from East Asia to organizations in the U.K., Germany, Italy and South Africa, using malware such as Atlas RAT, RomulusLoader and SilentRunLoader, according to a Proofpoint technical analysis.









