Welcome to LoopSec

We are a group that is focused on teaching others how to program and exposing any corruption we might run into. If you would like any assistence or would like to join us then please apply. Please sign in/sign up to view the full site.

 




The Hacker News
  • Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
    Saturday, 25. July 2026 20:48 o'clock
    A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and
  • Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
    Saturday, 25. July 2026 14:52 o'clock
    Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires
  • Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
    Saturday, 25. July 2026 12:14 o'clock
    Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update. Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap
  • CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
    Saturday, 25. July 2026 12:14 o'clock
    For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting
  • Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
    Saturday, 25. July 2026 12:14 o'clock
    Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling
  • DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
    Saturday, 25. July 2026 11:53 o'clock
    The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis. "The portal combined build generation, finance,
My Account



Not a member yet? Sign up now!