Steam C2 Backdoor
GoDaddy says WordPress malware hides C2 data in Steam profile comments. Check for hello-mywordl.info, injected scripts, and PHP backdoors.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
GoDaddy says WordPress malware hides C2 data in Steam profile comments. Check for hello-mywordl.info, injected scripts, and PHP backdoors.
Dutch police and NCSC took down a botnet of at least 17 million infected devices. Here is what to check on PCs, routers, and…
ChatGPhish shows how a web page summarized by ChatGPT can surface phishing links, fake alerts, and QR codes inside a trusted AI answer.
FortiClient EMS CVE-2026-35616 was abused to push EKZ Infostealer as a fake patch. Check EMS logs, managed endpoints, browser credentials, and hotfixes.
CISA added PAN-OS CVE-2026-0257 to KEV after exploitation. Check GlobalProtect portals and gateways, patch PAN-OS, and disable unsafe authentication override cookies.
Rapid7 disclosed a critical unpatched Gogs RCE path. Check open registration, repository creation, and rebase merge settings now.
sysupdate.jpeg malware is a fake image loader tied to Operation SilentCanvas. Learn what to check, how ScreenConnect is abused, and how to clean Windows…
Downloaded CPU-Z or HWMonitor during the CPUID compromise? Check the April 9-10 window, CRYPTBASE.dll, browser passwords, and clean up safely.
TrapDoor spreads malicious packages through npm, PyPI and Crates.io, steals developer secrets, and hides instructions in CLAUDE.md and .cursorrules.