#popular


Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Jun 15, 2026 // 22:50

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into […]

Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials

May 19, 2026 // 09:36

In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials […]

Popular node-ipc npm package compromised to steal credentials

May 15, 2026 // 23:57

Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. The […]

Popular WordPress redirect plugin hid dormant backdoor for years

Apr 30, 2026 // 01:16

The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users’ […]

AnimePlay app, popular with 5M users, shut down by anti-piracy group.

Mar 27, 2026 // 13:57

The Alliance for Creativity and Entertainment (ACE) has closed down AnimePlay, a popular anime streaming website with over 5 million users. ACE, supported by over […]

Critical flaw in popular VoIP phones enables unauthenticated remote access and eavesdropping.

Feb 20, 2026 // 16:23

A critical vulnerability, CVE-2026-2329 (CVSS 9.3), has been discovered in Grandstream GXP1600 series VoIP phones, allowing unauthenticated attackers to gain root-level control. Key Details Critical Impacts Remediation