RSS
Threat Research
featured
Gootkit
Gootloader
HelloDolly
JScript
malicious SEO
malware
obfuscation
php
PHP shell
SEO
WordPress
YARA
Gootloader inside out
Naked Security
Packagist
Supply chain
PHP Packagist supply chain poisoned by hacker “looking for a job”
cryptograhpy
CVE-2022-37454
sha-3
SHA-3 code execution bug patched in PHP – check your version!
exfiltration
Python
SecOps
XDR
Poisoned Python and PHP packages purloin passwords for AWS access
CVE-2021-21708
use-after-free
Irony alert! PHP fixes security flaw in input validation code
Android
Apple
Flubot
iOS
vulnerability
Zero-day
S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug [Podcast]
Composer
PHP community sidesteps its third supply chain attack in three years
cryptography
Exploit
OpenSSL
S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor [Podcast]
Backdoor
webshell
PHP web language narrowly avoids “backdoor” supply chain attack