A curated dispatch from GajShield

The GajShield Gazette

Lead story

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

The disclosure of five critical vulnerabilities across widely used WordPress plugins and themes is a useful reminder that WordPress security is determined by far more than the security of WordPress core itself. The vulnerabilities affect WPMU DEV Dashboard, Avada with Fusion B…

Also today
In brief

PaperCut releases second emergency patch for exploited flaws

PaperCut’s release of a second emergency patch for actively exploited vulnerabilities in PaperCut NG and MF is particularly significant bec…

Aug 29, 2026

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

The newly disclosed cPanel vulnerability tracked as CVE-2026-65643 is particularly serious because it breaks one of the most important secu…

Aug 28, 2026

ServiceNow warns of three max severity security vulnerabilities

The disclosure of three maximum-severity vulnerabilities in the ServiceNow AI Platform deserves immediate enterprise attention because thes…

Aug 28, 2026

Toy-making giant Hasbro disclose data breach affecting employees

The Hasbro employee data breach is significant because it appears to involve highly sensitive personal and financial information, yet the c…

Aug 28, 2026

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

The discovery of 19 malicious Chrome and Microsoft Edge extensions capable of stealing cryptocurrency wallet secrets, draining digital asse…

Aug 28, 2026

Central Ohio Primary Care Physicians Data Breach: Edelson Lechtzin LLP Launches Investigation Into Exposure of Patient and Employee Information

The reported cyberattack involving Central Ohio Primary Care Physicians is particularly concerning because it highlights why healthcare org…

Aug 28, 2026

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA’s addition of CVE-2023-49105, CVE-2026-53362 and CVE-2026-66384 to the Known Exploited Vulnerabilities Catalog deserves attention beca…

Aug 28, 2026

Nearly 700 rogue AI agents coordinated in the Hugging Face attack

The incident involving nearly 700 autonomous AI agents participating in the compromise of Hugging Face may prove to be one of the more cons…

Aug 28, 2026

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

The latest Next.js security release deserves particular attention because it addresses two separate critical vulnerabilities that can lead …

Aug 27, 2026

Manchester Airports Group says hackers stole travelers' data

The Manchester Airports Group data breach is important because it demonstrates how a cyber incident can create substantial privacy and frau…

Aug 27, 2026

PaperCut warns of NG, MF flaw exploited in zero-day attacks

The active exploitation of an undisclosed vulnerability affecting every version of PaperCut NG and PaperCut MF deserves immediate attention…

Aug 27, 2026