Aggregator
Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data
A sweeping cyberattack campaign has compromised more than 7,500 Magento-powered e-commerce websites since late February 2026, with attackers uploading hidden malicious files into publicly accessible web directories across thousands of domains. The attack has spread to over 15,000 hostnames, affecting commercial brands, government agencies, universities, and non-profit organizations spanning multiple countries, making it one of […]
The post Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data appeared first on Cyber Security News.
2268 кг бомба пробивает бетон, уходит вглубь и взрывается внутри — США применили GBU-72 против Ирана
Chainguard Assemble 2026 and the Security Factory Mindset
From golden images to agent governance, Chainguard Assemble 2026 focused on how teams can reduce risk by embedding trust, compliance, and security into delivery systems.
The post Chainguard Assemble 2026 and the Security Factory Mindset appeared first on Security Boulevard.
BSidesSLC 2025 – Getting Things Fixed – Keynote On Security Wins (And Fails)
Author, Creator & Presenter: Scott Piper - Principal Cloud Security Researcher at Wiz
Our thanks to BSidesSLC for publishing their Creators, Authors and Presenter’s outstanding BSidesSLC 2025 content on the Organizations' YouTube Channel.
The post BSidesSLC 2025 – Getting Things Fixed – Keynote On Security Wins (And Fails) appeared first on Security Boulevard.
arXiv 的独立之路
CVE-2026-33368 | Zimbra Collaboration Suite 10.0/10.1 Webmail REST Interface /h/rest cross site scripting
CVE-2026-33370 | Zimbra Collaboration Suite 10.0/10.1 Briefcase Feature cross site scripting (EUVD-2026-13694)
CVE-2026-33372 | Zimbra Collaboration Suite 10.0/10.1 Request Header cross-site request forgery (EUVD-2026-13698)
CVE-2026-33371 | Zimbra Collaboration Suite 10.0/10.1 Exchange Web Service xml external entity reference (EUVD-2026-13696)
CVE-2026-33369 | Zimbra Collaboration Suite 10.0/10.1 Mailbox SOAP Service ldap injection
CVE-2026-4516 | Foundation Agents MetaGPT up to 0.8.1 DataInterpreter write_analysis_code.py injection
CVE-2026-4515 | Foundation Agents MetaGPT up to 0.8.1 operator.py code_generate code injection
New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation
A newly identified variant of the VoidStealer infostealer has drawn serious attention from the security community after it became the first malware known to bypass Google Chrome’s Application-Bound Encryption (ABE) without requiring code injection or elevated system privileges. The variant, introduced in VoidStealer version 2.0 on March 13, 2026, uses a debugger-based technique to silently […]
The post New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation appeared first on Cyber Security News.