CODER'S REGISTRY HACKED TO DISTRIBUTE MALWARE
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.
■ MORE FROM THE SECURITY DESK
A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.
Utah will not enforce its groundbreaking VPN age-verification law while a legal challenge proceeds through the courts. The state became the first to target VPN usage alongside broader age-verification requirements.
A critical vulnerability in Elementor Pro for WordPress is being actively exploited to inject webshells and execute arbitrary commands on compromised servers. The flaw, tracked as CVE-2026-32475, has been patched but attackers are already targeting unpatched installations.
Passwords found in infostealer logs represent just one piece of a larger breach. Attackers gain access to authenticated sessions that can bypass multi-factor authentication, creating immediate account takeover risks.