Newsgather

hijacking

Stabil15 Meldungen14 QuellenZuletzt aktualisiert: 8.7.2026

Neueste Meldungen

Adult Content Creators' Copyright Takedowns Hijack Government Websites
In Entwicklung
Technik·8.7.2026KI-Zusammenfassung

Adult Content Creators' Copyright Takedowns Hijack Government Websites

Adult content creators are filing millions of copyright takedown requests, inadvertently leading to the compromise of thousands of government and university websites globally. Scammers exploit these official domains to push malicious links and scams, using creator names as bait. While DMCA requests aim to protect content, they highlight vulnerabilities in official web infrastructure.

W
Wired
Critical cPanel Vulnerability Allows Full Server Hijacking, Researchers Warn
EILMELDUNG
Technik·30.4.2026KI-Zusammenfassung

Critical cPanel Vulnerability Allows Full Server Hijacking, Researchers Warn

Security researchers have discovered a critical vulnerability (CVE-2026-41940) in cPanel and WebHost Manager that allows remote attackers to bypass authentication and gain full administrative control of servers. The flaw affects all supported versions of the widely-used web hosting software, estimated to be used by tens of millions of website owners. Canada's cybersecurity agency warns exploitation is highly probable, prompting major hosting providers including Namecheap and Hostgator to patch systems. KnownHost discovered evidence of active exploitation dating back to February.

T
TechCrunch
1 Min. Lesezeit
Malicious Bitwarden CLI Package Exfiltrated Infrastructure Credentials via Compromised npm Release
In Entwicklung
Technik·24.4.2026KI-Zusammenfassung

Malicious Bitwarden CLI Package Exfiltrated Infrastructure Credentials via Compromised npm Release

On April 22, 2026, a malicious version of Bitwarden's command-line interface was published to npm under the official package name @bitwarden/[email protected], remaining available for 93 minutes. The compromised package targeted infrastructure credentials including GitHub tokens, npm tokens, SSH keys, AWS/GCP/Azure credentials, and GitHub Actions secrets. Security firm JFrog analyzed the payload and found it had no interest in Bitwarden vaults—only in credentials governing build, deployment, and infrastructure automation. Bitwarden confirmed the incident is connected to the broader Checkmarx supply chain campaign and found no evidence of end-user vault access or production system compromise.

C
CryptoSlate
4 Min. Lesezeit