WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the...
Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the...
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The...
Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365...
Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000...
Journalists and civil society are being silenced by accusations of copyright infringement, says Alberto Fittarelli in a report by the OCCRP. The post Inside the Fake Copyright Racket Silencing...
Google security advisory (AV26-787)
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS...
A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”
The cyberattack hit gate systems at all three North Carolina ports, as officials continue investigating the breach and its effects on operations. The post Coast Guard says it is monitoring...
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS...
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was...
Cisco security advisory (AV26-757)
GitLab security advisory (AV26-758)
Spring security advisory (AV26-759)
Adobe security advisory (AV26-760)
WebPros security advisory (AV26-761)
[Control Systems] Phoenix Contact security advisory (AV26-762)
PHP Group security advisory (AV26-764)
Gladinet security advisory (AV26-765)
SolarWinds security advisory (AV26-766)
Rails security advisory (AV26-767)
Google security advisory (AV26-768)
IBM security advisory (AV26-770)
Dell security advisory (AV26-771)
Tenable, Inc. security advisory (AV26-773)
Checkpoint security advisory (AV26-774)
MISP security advisory (AV26-775)
N-able security advisory (AV26-769) - Update 1
Adobe security advisory (AV26-776)
Zyxel security advisory (AV26-780)
Progress security advisory (AV26-781)
Jenkins security advisory (AV26-782)
GitHub security advisory (AV26-783)
Foxit security advisory (AV26-784)
Intruder gained access to engineering files and potentially export-controlled technical data
The LevelBlue OpsCTI Team recently identified a large-scale phishing campaign leveraging a new social engineering method to deploy unauthorized ConnectWise ScreenConnect clients. Rather than...
Snowflake hacker's guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop's worm spreads via npm.
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, indicating the group has been compromising internet-facing...
Humans will get the AI models they deserve
Through data brokers, ICE is buying the information you provided to open a credit card.
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard...
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents...
In July 2026, Exact Sciences (now owned by Abbott Laboratories) was the target of a ShinyHunters "pay or leak" extortion campaign. The group claimed to have obtained data from the company's cancer...
Beijing’s not saying why, which is just what happened when it investigated Micron
Cisco security advisory (AV26-785)
Django security advisory (AV26-786)
AI usage is evident but isn't yet a serious problem