Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Berlin confirms an extortion attempt after data theft from its state network, while the scope of the exfiltrated data remains ...
GoCaracal gave operators remote shell access and browser data theft during a June 2026 intrusion at a Venezuelan ...
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two ...
Android 17 adds OS-wide ECH, local network permissions, default certificate transparency, and carrier-controlled 2G blocking.
PaperCut says a zero-day affecting all NG and MF versions is actively exploited; emergency patches are available for v25 and ...
Two Unitree G1 EDU vulnerabilities enable separate root RCE chains, including a BLE path; fixed firmware versions remain ...
CISA adds CVE-2026-60004 to KEV amid active Gitea RCE exploitation; a separate reported attack deployed a miner-like dropper.
Spark RAT targets Cambodia through a multi-stage campaign that uses a vulnerable OPSWAT driver to terminate security ...
Panel patches CVE-2026-65643, a critical flaw that lets authenticated accounts with domain controls execute code as root.
Australian police charged two men over their alleged TeamPCP role in supply chain compromises affecting Trivy, KICS, and ...
INTERPOL's Operation Jackal IV arrests 58 people, identifies 263 suspects, and disrupts fraud and laundering networks across ...