Cybersecurity News
-
GiveWP Fixes Critical WordPress Flaw Allowing Remote Code Execution
Security researchers at Patchstack has disclosed a critical vulnerability in the popular GiveWP WordPress donation plugin that could allow an unauthenticated attacker to execute commands on an affected website’s server. GiveWP is…
-
PaperCut Releases Emergency Patch as Attackers Exploit Critical Security Flaws
PaperCut has released a second emergency security update for its widely used NG and MF print management software after confirming that attackers are actively exploiting vulnerabilities in customer environments. The incident involves…
-
Anthropic Says Claude Can Automate Parts of AI Safety Research
Anthropic says Claude can automate parts of AI safety research, including independently finding and testing methods for reducing several kinds of problematic AI behavior, suggesting that some alignment research could be automated…
-
Brave Browser Adds Built-In Email Aliases to Hide Your Real Address
Brave has added an email alias feature to its desktop browser, giving users a way to sign up for websites without handing over their primary email address. The new Email Aliases feature…
-
19 Chrome and Edge Extensions Found Carrying Password & Crypto-Stealing Malware
Researchers at Socket have uncovered 19 malicious browser extensions capable of stealing login information, targeting cryptocurrency wallets and delivering additional malicious code. The investigation identified 18 Chrome extensions and one Microsoft Edge…
-
Android 17 Adds New Network Protections Against Snooping and Text Scams
Google is introducing four new network protections in Android 17 designed to make web browsing, Wi-Fi connections and mobile networks more private and harder for attackers to exploit. The changes address several…
-
cPanel Fixes Domain Parking Flaw That Could Give Attackers Root Access
cPanel has released security updates to fix a serious vulnerability in its domain parking and addon domain functionality that could allow an authenticated hosting user to gain full control of a server.…
-
Critical Next.js Flaw Leaves Some Windows Servers Open to Remote Code Execution
Developers running certain Next.js applications on Windows are being urged to update after a critical vulnerability was found that could allow attackers to execute code remotely without logging in first. The flaw,…
-
Ring Is Changing How Security Camera Videos Are Encrypted by Default
Ring is introducing a new encryption system for security camera footage that is designed to give customers more control over their recordings while keeping cloud-based features available. Called TAKE, or Throw Away…
