RSS
Threat Research
featured
Gootkit
Gootloader
HelloDolly
JScript
malicious SEO
malware
obfuscation
php
PHP shell
SEO
WordPress
YARA
Gootloader inside out
January 16, 2025
Naked Security
Packagist
Supply chain
PHP Packagist supply chain poisoned by hacker “looking for a job”
May 5, 2023
cryptograhpy
CVE-2022-37454
sha-3
SHA-3 code execution bug patched in PHP – check your version!
November 1, 2022
exfiltration
Python
SecOps
XDR
Poisoned Python and PHP packages purloin passwords for AWS access
May 25, 2022
CVE-2021-21708
use-after-free
Irony alert! PHP fixes security flaw in input validation code
February 18, 2022
Android
Apple
Flubot
iOS
vulnerability
Zero-day
S3 Ep31: Apple zero-days, Flubot scammers and PHP supply chain bug [Podcast]
May 6, 2021
Composer
PHP community sidesteps its third supply chain attack in three years
April 30, 2021
cryptography
Exploit
OpenSSL
S3 Ep26: Apple 0-day, crypto vulnerabilities and PHP backdoor [Podcast]
April 1, 2021
Backdoor
webshell
PHP web language narrowly avoids “backdoor” supply chain attack
March 30, 2021