A critical unauthenticated Remote Code Execution (RCE) vulnerability has been discovered in DSL-3788 routers, allowing remote attackers to gain full control. Found in firmware versions v1.01R1B036_EU_EN and earlier, the flaw involves improper input validation in the webproc CGI component. D-Link has released a patch, urging users to update their devices to enhance security.
Hackers Abusing GitHub Infrastructure to Deliver Lumma Stealer
Researchers have discovered a complex campaign using GitHub’s infrastructure to spread the Lumma Stealer malware. This malware steals sensitive data and deploys additional hostile payloads.