PHP

Six Malicious Packagist Themes Deliver Trojanized jQuery Payloads

Security researchers have identified six malicious Composer packages on Packagist that claim to be legitimate OphimCMS themes, a Laravel-based content management system used for...

PHPT Vulnerability Exposes CI/CD Pipelines to Remote Code Execution Attacks

The vulnerability resides in the cleanupForCoverage() method, which deserializes code coverage data files without validating input or restricting allowed object classes. An attacker with local file...

PHP PDO Flaw Allows Hackers to Inject Malicious SQL

A cybersecurity researcher has disclosed a groundbreaking SQL injection technique that can bypass PHP's PDO prepared statements, traditionally considered one of the most secure...

Stealthy Malware on WordPress Sites Delivers Windows Trojan via PHP Backdoor

A sophisticated malware campaign has been discovered targeting WordPress websites, leveraging a stealthy PHP backdoor to deliver a Windows-based Remote Access Trojan (RAT) to...

PHP XXE Vulnerability Exposes Config Files & Private Keys to Attackers

A critical vulnerability in PHP's XML parsing mechanisms has been uncovered, enabling attackers to bypass multiple security restrictions and gain unauthorized access to sensitive...

Popular

Subscribe