Critical Kirki flaw exploited to hijack WordPress admin accounts
Critical Kirki Flaw Exploited to Hijack WordPress Admin AccountsHackers are actively exploiting a critical privilege escalation vulnerability in the Kirki plugin for WordPress, tracked as CVE-2026-8206. The flaw affects…
Jun 04, 2026
New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
HTTP/2 Bomb Vulnerability: Small Requests, Big Denial-of-Service ImpactSecurity researchers have disclosed a new remote denial-of-service technique called HTTP/2 Bomb, affecting major web servers and infrastructure comp…
Jun 04, 2026
Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
Unpatched Windows Search URI Issue Can Leak NTLMv2 HashesSecurity researchers have disclosed an unpatched Windows Search URI issue that could allow attackers to steal a user’s NTLMv2 hash. According to The Hacker News, …
Jun 03, 2026
Acer working to patch max severity zero-days in Wave 7 routers
Acer Wave 7 Router Zero-Days: When the Network Gateway Becomes the Weak LinkAcer has warned about two maximum-severity vulnerabilities affecting its Wave 7 routers running firmware version T7c_GBL_1.01.000055 or earlier…
Jun 03, 2026
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
## One-Click GitHub.dev Attack Shows Why Developer Tools Are High-Value TargetsA newly disclosed vulnerability in GitHub.dev and VS Code’s web-based environment shows how a single click could allow attackers to steal a …
Jun 03, 2026
CISA warns of active attacks exploiting Android, Linux bugs
## CISA Warns of Active Exploitation of Android and Linux VulnerabilitiesCISA has warned that attackers are actively exploiting two vulnerabilities affecting Android and Linux systems. The first, CVE-2025-48595, is a hi…
Jun 03, 2026
WordPress malware campaign hides payloads in Steam profiles
## WordPress Malware Campaign Hides Payloads in Steam ProfilesA new malware campaign has infected nearly 2,000 WordPress websites by hiding command-and-control data inside Steam Community profile comments. According to …
Jun 02, 2026
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Meta AI Support Bot Abuse: When Account Recovery Becomes the Attack PathHackers reportedly abused Meta’s AI-powered support assistant to take over Instagram accounts, including high-profile accounts such as the **Obama …
Jun 02, 2026
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
## Hackers Hijack Thousands of Sites for ClickFix and FakeUpdate Attacks: Trust Is Being Weaponized AgainA new report covered by BleepingComputer highlights how a threat actor tracked as **DriveSurge** has been running …
Jun 02, 2026
Dashlane Brute-Force Attack: A Reminder That Identity Is Now the Front Door
Dashlane Brute-Force Attack: A Reminder That Identity Is Now the Front DoorDashlane has disclosed that some user accounts were targeted in a brute-force attack by an external threat actor. According to reports, the atta…
Jun 02, 2026
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
The active exploitation of Palo Alto Networks GlobalProtect CVE-2026-0257 is a serious reminder that VPN gateways remain one of the most attractive entry points into corporate networks. The flaw allows attackers to bypa…
Jun 01, 2026
Unidentified RAT pushes NetSupport RAT, (Mon, Jun 1st)
The SANS ISC diary on an unidentified RAT pushing NetSupport RAT is a good reminder that ClickFix campaigns are becoming a reliable malware delivery method. In this case, the infection originated from the SmartApeSG Cli…
Jun 01, 2026