-
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Red Hat has disclosed a critical vulnerability in the Red Hat Build of Keycloak that allows an unauthenticated remote attacker to bypass a key safeguard in the password reset process and seize control of arbitrary user accounts. Tracked as CVE-2026-189…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are using sponsored Google Search ads to place a fake OpenAI Codex download page above the legitimate result, steering macOS users into manually executing malware through Terminal. The operation begins when users search for Codex-related …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
EvilTokens is pushing phishing-as-a-service beyond credential theft by abusing Microsoft’s device authorization flow to obtain valid Microsoft 365 tokens. Victims can complete a legitimate Microsoft sign-in and MFA challenge, yet unknowingly authorize …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has released firmware updates for three Archer router models due to the discovery of multiple command injection vulnerabilities. These vulnerabilities could enable attackers to execute arbitrary operating system commands with root privileges. T…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are capitalizing on renewed interest in Grand Theft Auto VI by pushing fake Rockstar Games pages that advertise a non-existent GTA 6 demo but instead deliver the Vidar information stealer. The campaign targets browser credentials, sessio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A renewed distribution wave for the WeedHack malware-as-a-service operation, with threat actors continuing to push infected Minecraft clients and mods despite the campaign’s original command-and-control infrastructure being disrupted. The researchers f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Oracle HTTP Server to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation in the wild. The vulnerabili…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft is introducing a new Microsoft Teams meeting policy that automatically blocks identified external bots. This aims to address growing concerns regarding unauthorized AI notetakers, transcription tools, and recording assistants that may enter s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments on Windows, macOS, and Linux. The issues incl…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


