Chinese cybersecurity researchers have uncovered a PHP backdoor, Glutton, believed to be from persistent threat goup Winnti. The malware has been found in China, the US, Cambodia, Pakistan and South Africa, undetected for over a year. The modular code operates within PHP or PHP-FPM optimised process handling on web servers, eliminating digital footprints and avoiding detection. Glutton can be used to extract data or inject malicious code into frequently used PHP frameworks.

Critical Vulnerability in MCP Server Platform Exposes 3,000+ Servers and Thousands of API Keys
A critical vulnerability in Smithery.ai, a popular registry for Model Context Protocol (MCP) servers. This issue could have allowed attackers to steal from over 3,000