Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Security News
botnet czBaTk

RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its BotnetThe Hacker Newsinfo@thehackernews.com (The Hacker News)

The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request […]

Security News
north hackers 9OGg3K

Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 CompaniesThe Hacker Newsinfo@thehackernews.com (The Hacker News)

The U.S. Department of Justice (DoJ) on Friday announced that five individuals have pleaded guilty to assisting North Korea’s illicit revenue generation schemes by enabling information technology (IT) worker fraud in violation of international sanctions. The five individuals are listed below – Audricus Phagnasay, 24 Jason Salazar, 30 Alexander Paul Travis, 34 Oleksandr Didenko, 28, […]

Security News
SecurityHomeImg

Honeypot: FortiWeb CVE-2025-64446 Exploits, (Sat, Nov 15th)SANS Internet Storm Center, InfoCON: green

Like many have reported, we too noticed exploit attempts for CVE-2025-64446 in our honeypots. These are POST requests to this path: With this User Agent String: And this is the data of the POST request: This creates a new admin user (profile: prof_admin). You can find this JSON data back in this PoC.   Didier Stevens […]

Security News
json QqB8TN

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels The Hacker Newsinfo@thehackernews.com (The Hacker News)

The North Korean threat actors behind the Contagious Interview campaign have once again tweaked their tactics by using JSON storage services to stage malicious payloads. “The threat actors have recently resorted to utilizing JSON storage services like JSON Keeper, JSONsilo, and npoint.io to host and deliver malware from trojanized code projects, with the lure,” NVISO […]