Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Source: The Hacker News The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at Read original

Hackers abuse npm mirrors to host phishing redirect pages

Hackers abuse npm mirrors to host phishing redirect pages Source: BleepingComputer Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. […] Read original

When str.lower() is a security vulnerability in Python

When str.lower() is a security vulnerability in Python Source: Hacker News Points: 96 Discussion: Hacker News Comments Read original

Hackers breached over 270 Zimbra servers in ongoing attacks

Hackers breached over 270 Zimbra servers in ongoing attacks Source: BleepingComputer Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. […] Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Source: The Hacker News Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. “While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t d Read original