A critical vulnerability in the Elementor Pro WordPress plugin is being actively exploited to upload malicious PHP files and execute commands remotely on…
Tag: CySecurity News – Latest Information Security and Hacking Incidents
AWS CodeCatalyst Blueprints SDK Hit by High-Severity Command Injection Flaw
There is a high-severity attack on Amazon CodeCatalyst blueprints that exploits an open-source framework for building them. This vulnerability has been…
Critical Nexus 9000 Flaw Could Permit Threat Actors to Gain Root Access
Cisco has issued security patches to fix a critical vulnerability impacting 10 Silicon One-based Nexus 9000 switches that could permit an unauthorized,…
Dropbox Says 5,000 Accounts Compromised After Flaw in Lenovo Login System
Dropbox has confirmed that hackers broke into roughly 5,000 user accounts last month by exploiting a weakness in how Lenovo verifies email addresses,…
Switchvox Vulnerability Triggers Active Exploitation Risk
Sangoma Switchvox CVE-2026-9586 is a serious unauthenticated SQL injection flaw that can lead to remote code execution, and Horizon3 says it has already…
redactproxy, a tool that lets pentesters use AI without leaking client data
AI coding agents are now part of a lot of security work. They are good at the parts a tester has no time for: going through every request, every parameter…
Thomson Reuters Court Records Breach Exposes Sensitive Data Across North America
Sensitive court records and personal information were spilled from a data breach in the court system, which impacts at least 12 states in the U.S.,…
Grafana MCP Flaw Exposes Session Spoofing and SSRF Risk
Grafana MCP has come under security scrutiny after researchers found a dangerous combination of unauthenticated tool access and server-side request…
1 Folder Was All It Took: Security Researchers Find AI Coding Agents Can Be Hijacked Before a Single Prompt Is Typed
Opening a folder should not be a security event. For users of at least seven popular AI coding agents, until recently, it could be one. A newly documented…
5 Million WordPress Sites Exposed to SQL Injection Vulnerability
A severe security flaw in a famous WordPress migration plugin and backup could allow threat actors to take command of over millions of sites, experts have…
Brazilian Government Site Compromised to Redirect Users to Betting Pages
An organization known as Gambling Goblin, which is a Chinese-speaking cybercrime group, has compromised Apache web servers owned by Brazilian government…
Sality Botnet Disrupted as Authorities Seize Key Infrastructure
An international public-private operation has disrupted Sality, a peer-to-peer botnet that remained active for more than two decades, by seizing domains…
Russian National Charged Over Malware Campaign Targeting 80,000 Freelancers
A Russian national has been extradited to the United States to face federal charges over an alleged malware campaign that targeted approximately 80,000…
Four Cybersecurity Habits That Can Do More Harm Than Good When Misused
Cybersecurity advice is often reduced to simple rules: change passwords regularly, avoid public Wi-Fi, install antivirus software and enable two-factor…
Received an Apple Threat Notification? How to Verify and Respond Safely
An Apple threat notification is not a routine security warning. Apple issues these high-confidence alerts when its threat intelligence indicates that…
Attackers Exploit CVE-2026-82329 to Forge JFrog Artifactory Admin Tokens
Cybersecurity researchers have observed attackers exploiting a critical JFrog Artifactory vulnerability shortly after its public disclosure. The flaw…
FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses
The FBI has opened an investigation into an apparent breach involving identity verification provider IDScan.net after a newly launched dark web service…
Hackers Hijack BGP Routes to Deliver Malicious Virtualizor Update
Hijackers compromised network routes used by Softaculous and redirected traffic to servers where they distributed a rogue Virtualizor update to a limited…
NSA Warning Exposes Common Router Security Risks
The recent warning from the NSA and partner agencies highlights a simple but important reality: routers are often the weakest link in a home or…
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing
Observations have shown that threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, with attacks moving beyond…
