Ghost CMS SQL Injection Fuels ClickFix Attacks on 700 Sites
Threat actors took advantage of a critical SQL injection vulnerability present in Ghost CMS to insert malicious Javascript code into ClickFix campaigns lau...
Found 25 relevant articles matching your search. Browse our cybersecurity insights and expert analysis below.
Threat actors took advantage of a critical SQL injection vulnerability present in Ghost CMS to insert malicious Javascript code into ClickFix campaigns lau...
Typically, when a sophisticated threat actor's primary malware is publicly exposed, they will take time to regroup from that event. However, that was not t...
During this tax season, Microsoft is alerting both individuals and companies about increased numbers of highly sophisticated phishing attacks that are aime...
According to Elastic Security Labs’ cybersecurity experts, they identified a highly advanced sophistication ClickFix campaign using legitimate websit...
A drive-by download is sneaky malware that can sneak onto your phone, laptop, or tablet just by visiting a website. You don’t have to click anything,...
Tornado (also known as Tornado Stealer, TornadoRAT, and other name variations such as Rhino Stealer variants) has emerged in the last couple of years as a...
MalwareBazaar is a free public malware sharing and intelligence platform hosted by abuse.ch (the organization running URLhaus, Feodo Tracker and SSL Blackl...
The Microsoft Defender team has issued an explicit alert that, for many years, malware has been a threat to Windows computer users; however, starting in la...
Our blog insights are backed by hands-on service delivery. Whether you need a penetration test, vulnerability assessment, emergency website recovery, or secure web development — our UK cybersecurity specialists are ready to help.
Emergency malware removal, backdoor elimination, blacklist delisting, and full post-incident hardening for compromised websites.
Authorised simulated attacks exposing real vulnerabilities in your web applications, networks, and infrastructure before attackers do.
Systematic identification and prioritisation of security weaknesses across your digital estate — with actionable remediation guidance.
OWASP-aligned web application development with security engineered in from architecture through to penetration-tested deployment.
Simulated, targeted adversarial attacks that test your people, processes, and technology under real-world conditions.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067