공격자들이 ClickFix 공격을 위해 700개의 Ghost CMS 사이트를 탈취함
CVE-2026-26980 SQL 인젝션 기반 700개 사이트 API 키 탈취
CVE-2026-26980 SQL 인젝션 기반 700개 사이트 API 키 탈취
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
Shai-Hulud copycat worm infects yet another npm package
The Coding Challenge That Came for Your development Directory: Anatomy of a Job Interview Infostealer
From the Perspective of a 20-Year Architect: My Own System's Security
Process Hollowing Detection: Your RAM is your treasure!
Trust as a Vector What the EtherRAT Campaign Reveals About Security's Blind Spot
Anatomy of a Low-Detection Credential Phishing Campaign
LetsDefend SOC250 - APT35 HyperScrape Data Exfiltration Tool Detected
공급망 침해를 통한 다단계 Secret 탈취 및 GitHub 인프라 무기화 공격
Trivy, KICS, and the shape of supply chain attacks so far in 2026
macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets
플러그인 31개 인수 및 Ethereum C2 기반 공급망 공격 사례
Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them
CPUID site hijacked to serve malware instead of HWMonitor downloads
That Fake Purchase Order in Your Inbox? It Might Be Formbook Stealing Every Keystroke You Type
I Traced a "Cute" Minecraft Phishing Site to a C2 Server in Chicago