Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin, allowing them to upload PHP backdoors and gain remote…
Tag: EN
ICE Wants to Know Who Bought a Certain Green Beanie From REI in the Last 2 Years
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of…
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to…
Plex Urges Users to Update Media Server as Multiple Security Flaws Are Discovered
Plex has urged users to promptly update their Plex Media Server and Plex Desktop software following the release of fixes for several undisclosed security…
OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential Services
OpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructure
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its…
Hackers Abuse AI-Era ASCII Smuggling to Hide Phishing Content in Millions of Emails
Threat actors have repurposed an AI prompt-injection technique known as ASCII smuggling to evade email security controls at massive scale, hiding…
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The…
Free streaming boxes may be routing criminal traffic through your home
Researchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.
G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules
The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition
Google fixes the sixth actively exploited Chrome zero-day of 2026
Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google…
Chinese-Speaking Hackers Use Claude, Qwen and DeepSeek AI Agents to Attack Government Systems
Chinese-speaking threat operators have been observed using Claude, Qwen and DeepSeek-powered AI agents as operational components in a second intrusion…
14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT
Mac users are being targeted with 14 fake application installers that appear to offer familiar software but instead start a credential-stealing…
Microsoft Teams is about to make QR code phishing much harder
Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by…
TP-Link Archer AX55 Flaws Enable Remote Code Execution and Admin Password Theft
TP-Link has released security updates for two vulnerabilities found in its Archer AX55 v4 wireless router. These vulnerabilities could allow attackers on…
Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices
A large campaign has compromised more than 14,000 internet-connected Dahua cameras, exposing how vulnerable surveillance equipment can become a gateway to…
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The…
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes…
Indirect Prompt Injection: How Hackers Attack RAG Applications (2026)
By HOC Team | Last updated: September 04, 2026 | Read time: ~28 min Indirect Prompt Injection: How…
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the “world’s most intelligent and aligned model.” The development comes days…