lithos Twitter
Lithos Header
Last Updated
Age in hrs 
1
2
3
5
8
13
21
34
55

 Thousands of CARS24 records exposed as customer leads allegedly go for just $11  - Exposed records include customer names, mobile numbers, and vehicle details.

 Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities  - Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass...

 G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules  - The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition

 Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain  - A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC).

 Chrome Dev for Android Update  - Hi everyone! We've just released Chrome Dev 155 (155.0.8040.0) for Android. It's now available on Google Play .

 New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic  - A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary....

 Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws  - Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder...

 Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores  - Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5 . Sansec, which discovered the flaw and...

 Angry Birds: Toy Ghouls’ new toys  - Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

 Pegasus spyware hits Serbian students and politicians in zero-click attack  - It’s the largest documented surveillance wave in Serbia to date.