Credential Theft

Technology

Ghost CMS SQL injection exploited in coordinated ClickFix campaign across 700+ sites

Universities and major platforms compromised via three-month-old unpatched vulnerability enabling malicious code injection and credential theft.

9 min read ·
Breaking Technology

Nx Console VS Code Extension Compromised in Supply Chain Attack Targeting Developer Credentials

Malicious v18.95.0 harvested cloud secrets and SSH keys from enterprise development environments during 11-minute window on Microsoft Marketplace.

7 min read ·