-
Linux administrators are being urged to patch four newly disclosed local privilege escalation (LPE) vulnerabilities, collectively known as DirtyAH6, TUNderflow, PPPoEject, and DiagSpill. These vulnerabilities can allow attackers to corrupt kernel memor…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
More than 100,000 WordPress sites using the Tutor LMS e-learning plugin were exposed to a high-severity remote code execution vulnerability that could allow low-privileged users to take control of vulnerable servers. The vulnerability was discovered on…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Researchers have identified significant security and privacy risks across 61,500 abandoned Android Internet-of-Things (IoT) companion applications. Their study found that 73.6% of these apps contained at least one potential vulnerability, risky embedde…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-2026-86863, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interact…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on Septe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security r…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


