CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to…
OptinMonster is a WordPress plugin for lead generation and email marketing, owned by Awesome Motive. Its JavaScript was tampered with for about…
axios is a popular npm package for making HTTP requests. It was compromised in March 2026 by Sapphire Sleet/UNC1069 via a post-install…
Mastra is an open-source JavaScript and TypeScript framework for building AI applications. In June 2026, 145 of its npm packages were compromised…
@mastra/core is the core npm package of the Mastra AI framework, receiving over 918K weekly downloads. It was among the 145 packages…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
easy-day-js is a malicious npm package that cloned the legitimate 'dayjs' date library. Published by user 'sergey2016', it initially appeared clean but…
Magecart is a collective of cybercriminal groups that specialize in web skimming attacks, injecting malicious scripts into e-commerce checkout pages to steal…
Sansec disclosed the wider campaign on June 13, finding the same malicious code in JavaScript served for all three plugins.
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels…