Topic: malicious comments

  • Beware: ClawHub Fake Fix Spreads Info-Stealing Malware

    Beware: ClawHub Fake Fix Spreads Info-Stealing Malware

    A new malware campaign targets ClawHub users by hiding malicious code within seemingly helpful comments on legitimate skills, bypassing traditional security scans that only inspect skill packages. The attack uses Base64-encoded comments to deploy a loader that fetches the AMOS infostealer, exploi...

    Read More »
  • Critical Vulnerability Found in W3 Total Cache WordPress Plugin

    Critical Vulnerability Found in W3 Total Cache WordPress Plugin

    A critical security flaw (CVE-2025-9501) in the W3 Total Cache WordPress plugin allows unauthenticated attackers to execute arbitrary PHP commands via specially crafted comments, affecting all versions before 2.8.13. The vulnerability, located in the `_parse_dynamic_mfunc()` function, was fixed i...

    Read More »