WP Maps Pro bug exploited to create admin accounts on WordPress sites
The active exploitation of the WP Maps Pro vulnerability is another reminder that WordPress plugins can become full site-takeover paths when access controls are weak. The flaw, tracked as CVE-2026-8732, affects WP Maps …
Jun 01, 2026
New CIFSwitch Linux flaw gives root on multiple distributions
The CIFSwitch Linux vulnerability is a serious reminder that local privilege escalation bugs can be just as dangerous as remote exploits once an attacker has any foothold on a system. The flaw affects the Linux kernel’s…
Jun 01, 2026
ChatGPT share links abused to host fake outage pages to deliver malware
The abuse of ChatGPT share links to host fake outage pages is a reminder that attackers will exploit user trust in legitimate platforms, not just fake domains. According to the report, threat actors are using ChatGPT’s …
May 30, 2026
California AG sues 23andMe over 2023 breach exposing health data
The California Attorney General’s lawsuit against 23andMe is a reminder that genetic-data breaches are in a completely different category from ordinary account compromises. According to the report, the 2023 breach expos…
May 30, 2026
BTMOB Android malware service generates custom phishing payloads
The BTMOB Android malware service shows how mobile malware is becoming easier for criminals to deploy at scale. According to the report, BTMOB is being sold as a malware-as-a-service platform with a builder that lets at…
May 29, 2026
FBI warns of fake FIFA websites running World Cup fraud schemes
The FBI’s warning about fake FIFA websites is an important reminder for football fans: scammers are already exploiting excitement around the 2026 World Cup. Fake websites are being created to look like official FIFA pag…
May 29, 2026
Hackers exploit FortiClient EMS flaw to push infostealer malware
The FortiClient EMS exploitation campaign is a serious reminder that endpoint management platforms can become malware delivery systems if they are compromised. Attackers are exploiting CVE-2026-35616, an authentication …
May 29, 2026
Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code
The critical Gogs RCE vulnerability is a serious reminder that self-hosted Git platforms are not just internal developer conveniences. They are part of the software supply-chain control plane. The flaw carries a CVSS 9.…
May 29, 2026
Charter Communications data breach affects 4.9 million accounts
The Charter Communications breach update shows why early breach claims and final exposure counts need careful handling. Have I Been Pwned now lists the Charter incident as affecting 4.9 million accounts, while ShinyHunt…
May 29, 2026
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
The Marimo CVE-2026-39987 incident is a major warning sign for defenders: attackers are now using LLM agents not just for research or phishing, but for live post-exploitation activity. In this case, an internet-exposed …
May 29, 2026
Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets
The malicious Sicoob.Sdk NuGet package is another reminder that software supply-chain attacks are now targeting business integrations, not just generic developer environments. According to the report, the package impers…
May 29, 2026
Google Chrome adds session cookie theft protection for all users
Google Chrome’s rollout of Device Bound Session Credentials is an important step against one of the most damaging modern attack techniques: session cookie theft. Infostealer malware often steals browser cookies after a …
May 29, 2026