Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

SecurityWeek
securityweek.com > malicious-virtualizor-update-served-via-bgp-hijacking

Malicious Virtualizor Update Served via BGP Hijacking

1+ week, 4+ day ago   (737+ words) Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers. A…...

SecurityWeek
securityweek.com > 23-year-old-sality-p2p-botnet-disrupted

23-Year-Old Sality P2P Botnet Disrupted

1+ week, 4+ day ago   (538+ words) The shutdown operation involved peer list manipulation and Sality payload URL takedown. After 23 years of operation, the Sality peer-to-peer (P2P) botnet has been disrupted as part of an international law enforcement effort. First observed in 2003, Sality has been used for distributing…...

SecurityWeek
securityweek.com > wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities > amp

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

2+ week, 5+ day ago   (430+ words) Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin. The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for…...

SecurityWeek
securityweek.com > new-phishing-toolkit-uses-passkeys-to-maintain-access-after-password-resets

New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets

3+ week, 2+ day ago   (597+ words) Researchers say iAuthFlow V2 can register an attacker-controlled passkey, enabling persistent access even after passwords are changed and active sessions revoked. iAuthFlow V2 is a new phishing toolkit demonstrating the rapidly improving sophistication of phishing techniques. iAuthFlow V2 is a malware toolkit first…...