An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into […]
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials […]
Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication package, in a new supply chain attack targeting npm. The […]
The Quick Page/Post Redirect plugin, installed on more than 70,000 WordPress sites, had a backdoor added five years ago that allows injecting arbitrary code into users’ […]
The Alliance for Creativity and Entertainment (ACE) has closed down AnimePlay, a popular anime streaming website with over 5 million users. ACE, supported by over […]
A critical vulnerability, CVE-2026-2329 (CVSS 9.3), has been discovered in Grandstream GXP1600 series VoIP phones, allowing unauthenticated attackers to gain root-level control. Key Details Critical Impacts Remediation
© Bulletproof Servers. All rights reserved.