CrowdStrike security researchers discovered two Docker images with over 150,000 downloads that were used to launch distributed denial-of-service (DDoS) attacks on a dozen Russian and Belarusian websites operated by government, military, and press organisations from February to March 2022. CrowdStrike discovered that two malicious images named "Erikmnkl/stoppropaganda" and "Abagayev/stop-Russia" retrieved directly from the Docker Hub repository attacked its honeypots via exposed Docker Engine APIs. Initially, the targets for the DDoS attacks were chosen at random, but subsequent versions of the images included a time-based selection and a hardcoded list of targets that were targeted in one-hour strikes. The Docker images contains bombardier, a Go-based HTTP benchmarking tool for stress-testing websites using HTTP-based queries that was abused as a DoS tool when a new container based on the Docker image was created. Targeting unprotected Docker APIs is nothing new; cryptocurrency mining gangs such as Lemon Duck and TeamTNT have been targeting exposed Docker APIs for years. Unfortunately, there are many poorly configured or poorly protected Docker deployments out there, making it simple for threat actors to exploit the resources.
WordPress 7.0.3 resolves roughly a dozen security issues, including a high-severity reflected cross-site scripting (XSS) vulnerability identified as CVE-2026-64638, which has a CVS...
VulnCheck researchers have disclosed a critical backdoor named ENDLESSDOORS, tracked as CVE-2026-66747, affecting every published firmware version for Zbtlink routers, including th...
Coinspect has traced the recent Ill Bloom cryptocurrency wallet drains to the weak random number generator CryptoJS.lib. WordArray.random(), a flaw introduced into the CryptoJS Jav...