Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Critical Vulnerabilities in Popular WordPress Plugins and Themes
Researchers from Wordfence and Patchstack have disclosed five critical vulnerabilities (CVSS 9.8–10.0) in widely used WordPress plugins and themes — ...
How Android 17 Hardens Network Security with ECH and 2G Controls
Android 17 (API level 37) introduces four major network security improvements: platform support for Encrypted Client Hello (ECH) to hide ...
Superior campaign: wallet-draining malware in browser extensions
Researchers at Socket identified a cluster of 19 malicious extensions — 18 for Google Chrome and one for Microsoft Edge ...
Chinese-Speaking Operator Uses ownCloud Flaw to Hack Philippine Nuclear Center
CISA has added the critical vulnerability CVE-2023-49105 (CVSS 9.8) in the ownCloud platform to the Known Exploited Vulnerabilities (KEV) catalog ...
Root-level remote code execution chains in Unitree G1 EDU robots
Security researcher Olivier Laflamme published details on August 27, 2026 of two independent remote code execution chains with root privileges ...
CISA Flags Citrix NetScaler Bug and Five Other CVEs in KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August ...
How WordlistLoader and SynkLoader expand Windows malware delivery
Researchers from Gen Digital and Expel independently identified two previously unknown malware loaders — WordlistLoader and SynkLoader — each using ...
Marimo notebook flaw lets malicious MCP commands run on open
The interactive notebook Marimo has patched a high-severity vulnerability CVE-2026-75149 that allowed an attacker to inject an arbitrary Model Context ...
How a Forminator Forms File Upload Bug Exposes 600,000 WordPress Sites
A critical arbitrary file upload vulnerability has been discovered in the Forminator Forms plugin for WordPress, allowing an unauthenticated attacker ...
How China’s QTFY Used QScan/QTRouter Against US Infrastructure
The US Department of Justice announced the takedown of two hacking platforms — QScan and QTRouter — which, according to ...