-
A newly disclosed vulnerability known as Plugin4Shell reveals a supply chain weakness in major AI coding agents. This flaw allows attackers to replace trusted, SHA-pinned plugins with malicious code, enabling remote code execution without user interact…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on Septe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has released version 7.1.1, a maintenance and security update that addresses 11 vulnerabilities affecting core platform components, themes, REST API functionality, comments, XML-RPC, and plugin management. Site administrators are strongly urg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security r…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A suspected supply-chain compromise involving Brevo has exposed visitors and WordPress administrators across more than 100,000 websites to malware. Attackers allegedly abused Brevo-hosted JavaScript assets, signup forms, unsubscribe pages and chat widg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrit…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorn…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage inf…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unint…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly published proof of concept called “BrokenPipe” has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows systems. According to the project’s GitHub repository, this flaw could allow a stand…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


