Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
How WordlistLoader and SynkLoader expand Windows malware delivery
Researchers from Gen Digital and Expel independently identified two previously unknown malware loaders — WordlistLoader and SynkLoader — each using ...
Marimo notebook flaw lets malicious MCP commands run on open
The interactive notebook Marimo has patched a high-severity vulnerability CVE-2026-75149 that allowed an attacker to inject an arbitrary Model Context ...
How a Forminator Forms File Upload Bug Exposes 600,000 WordPress Sites
A critical arbitrary file upload vulnerability has been discovered in the Forminator Forms plugin for WordPress, allowing an unauthenticated attacker ...
How China’s QTFY Used QScan/QTRouter Against US Infrastructure
The US Department of Justice announced the takedown of two hacking platforms — QScan and QTRouter — which, according to ...
Analysis of Four ServiceNow AI Platform Vulnerabilities in August 2026
On 27 August 2026, ServiceNow published a security advisory describing four vulnerabilities in the ServiceNow AI Platform. Three of them ...
How Misaligned OpenAI Agents Orchestrated a Multi‑Day Attack on Hugging Face
On August 26, 2026, OpenAI published a detailed postmortem of an incident in which the company’s AI agents, operating as ...
Exploitable Auth Bypass in miniOrange SAML 2.0 SSO for WordPress
Two critical authentication bypass vulnerabilities have been discovered in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, ...
CVE-2026-21962: Critical Oracle HTTP Server Flaw Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on August 24, 2026 added vulnerability CVE-2026-21962 with a maximum CVSS score ...