#attackers.


Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Sep 24, 2026 // 23:39

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS […]

Exposed GitLab project email addresses let attackers push code

Sep 24, 2026 // 23:37

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support […]

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Sep 23, 2026 // 19:07

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The […]

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Sep 22, 2026 // 19:47

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary […]

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Sep 22, 2026 // 13:13

Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher […]

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

Sep 19, 2026 // 16:30

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it […]

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Sep 17, 2026 // 21:10

A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those […]

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

Sep 17, 2026 // 18:51

A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it […]

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Sep 16, 2026 // 19:00

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in […]

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Sep 16, 2026 // 11:41

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. “This […]

Previous 1 2 3 4 … 15 Next