Cybersecurity News
-
Why You Should Avoid Replying to Suspicious Texts
A text arrives from an unfamiliar number and appears to have been sent to the wrong person. Replying with a polite “wrong number” may seem harmless, but security researchers say some of…
-
Isolated-vm Flaw Could Let Sandboxed JavaScript Escape to Host
Security researchers at Endor Labs have disclosed a vulnerability in the popular isolated-vm Node.js library that can allow sandboxed JavaScript to break out of its restricted environment and interfere with the host…
-
Critical Elementor Pro Vulnerability Could Allow Remote Code Execution
A critical security flaw in Elementor Pro could allow unauthenticated attackers to upload malicious files to vulnerable WordPress websites and potentially take control of the underlying server. Tracked as CVE-2026-32475, the vulnerability…
-
Encrypted Prompt-Injection Attack Raises Data Privacy Concerns for xAI’s Grok
Security researchers have demonstrated a prompt-injection technique that may allow a malicious web page to trick xAI’s Grok chatbot into exposing information from an active conversation. AI security company Adversa AI calls…
-
Apple Releases iPhone and Mac Security Updates to Fix Code Execution Flaw
Apple has released new security updates for iPhone, iPad and Mac devices, addressing a number of vulnerabilities including an image-processing flaw that could allow arbitrary code execution. iOS 26.6.1 and iPadOS 26.6.1,…
-
Shadow AI Is Creating a Growing Visibility Gap for Security Teams
Businesses are struggling to keep track of how artificial intelligence is being used across their organizations as AI tools and features spread through workplace software. According to Bitdefender’s 2026 Cybersecurity Assessment, 51.8%…
-
Microsoft Patches One-Click Copilot Flaw That Could Expose User Data
Microsoft has patched a vulnerability in Copilot that researchers say could have allowed attackers to access and leak sensitive user data after a victim clicked a specially crafted link. The flaw, dubbed…
-
Critical WordPress Forminator Plugin Vulnerability Puts Affects 600K+ Sites at Risk
Security researchers at Wordfence have disclosed a critical security vulnerability in Forminator Forms, a popular WordPress form-building plugin with more than 600,000 active installations. The flaw, tracked as CVE-2026-15748, received a CVSS…
-
SafePal Confirms Data Breach Affecting Over 39K Customers
Crypto wallet maker SafePal has disclosed a data breach tied to a flaw in its order-tracking system on its official blog and via a post on X. The company says wallets, seed…
