Category: Security

Team of hackers with Guy Fawkes masks coding in a dark room with computers.
Security

CVE-2025-53521: F5 BIG-IP APM reclassified as critical RCE — what distinguishes active exploitation from earlier DoS assessments

F5‘s BIG-IP Access Policy Manager vulnerability CVE-2025-53521—originally treated as a denial-of-service issue—was reclassified as an unauthenticated remote code execution (RCE) after March 2026 intelligence showed active exploitation. The change forced CISA into the Known Exploited Vulnerabilities (KEV) list and triggered federal patch mandates; organizations must treat this as an immediate compromise risk, not a mere […]

admin 
silver MacBook on brown wooden table
Security

Infiniti Stealer is not a macOS exploit — it weaponizes ClickFix social engineering and Nuitka-compiled Python to bypass defenses

Infiniti Stealer is a recently documented macOS infostealer that relies on a fake CAPTCHA (the ClickFix technique) and a Nuitka-compiled Python payload to evade detection — it succeeds because it manipulates users, not by exploiting a software vulnerability. How the attack actually reaches a user In observed samples the initial lure is a Cloudflare-style CAPTCHA […]

admin 
Laptop displaying code with a coffee mug nearby.
Security

TeamPCP’s Telnyx Compromise: credential-based, steganographic backdoor in PyPI releases

On March 27, 2026 the Telnyx Python SDK on PyPI was backdoored by the actor known as TeamPCP using stolen maintainer credentials — not typosquatting. Malicious code landed only in telnyx/_client.py inside published releases 4.87.1 and 4.87.2 (no corresponding GitHub tags or releases), and the package’s ~700,000 monthly-download footprint made the trojanized SDK a high-value […]

admin 
Screens display coding text, representing programming work.
Security

Control the backend: ACE shuts down AnimePlay’s APK by seizing 29 GitHub repos and hosting in Riau

ACE (the Alliance for Creativity and Entertainment) has dismantled AnimePlay — an Android APK-based piracy app run from Riau, Indonesia — by seizing its entire backend: 29 GitHub repositories with source code, servers, databases, advertising tools, 15 domains and the hosting environment. AnimePlay had operated since 2020, amassed more than 5 million registered users and […]

admin 
Empty blue stadium seats with yellow accents
Security

Ajax breach warns clubs: shared digital key in ticketing app let attackers reassign tickets and lift stadium bans

Ajax Amsterdam’s early-2026 breach exposed a systemic flaw in its ticketing app: a shared digital key allowed mass unauthorized access to personal data and, crucially, to operational controls — reassigning more than 42,000 season tickets and flipping over 538 active stadium bans were all possible, not just isolated data reads. Who this matters for now: […]

admin 
man in white crew neck t-shirt sitting on brown chair
Security

GitHub’s CodeQL + AI detections: wider coverage and faster fixes — at the cost of continued human review

GitHub is rolling AI-powered security detections into the same workflow where developers review code, pairing those models with CodeQL static analysis to extend coverage into Shell/Bash, Dockerfiles, Terraform, PHP and other gaps in traditional scanning. The payoff is broader, earlier detection and faster remediation; the trade-off is additional governance and human review to catch AI […]

admin 
A man sitting on a train using a laptop computer
Security

CVE-2026-4681: Indicators of active attacks on PTC Windchill and FlexPLM — who must act now

CVE-2026-4681 is a critical remote-code-execution flaw in PTC Windchill PDMLink and FlexPLM tied to unsafe deserialization; independent detections show Indicators of Compromise (IOCs) consistent with active exploitation attempts, so organizations running affected versions should treat this as an incident in progress rather than a purely theoretical risk. Which deployments are at highest immediate risk The […]

admin