Credential Theft
Technology
Ghost CMS SQL injection exploited in coordinated ClickFix campaign across 700+ sites
Universities and major platforms compromised via three-month-old unpatched vulnerability enabling malicious code injection and credential theft.
Breaking
Technology
Nx Console VS Code Extension Compromised in Supply Chain Attack Targeting Developer Credentials
Malicious v18.95.0 harvested cloud secrets and SSH keys from enterprise development environments during 11-minute window on Microsoft Marketplace.