Cybersecurity News
-
Critical WordPress Plugin Flaw Exploited to Create Rogue Admin Accounts
A newly disclosed vulnerability in a widely used WordPress membership plugin is being actively exploited, allowing attackers to create administrator accounts and potentially take full control of affected websites. The flaw impacts…
-
LastPass Warns of Phishing Campaign Using Fake Email Chains
Password manager provider LastPass is warning customers about an ongoing phishing campaign designed to steal login credentials by impersonating legitimate account activity notifications. According to the LastPass’ Threat Intelligence, Mitigation, and Escalation…
-
Fake OpenClaw Installers Spread Malware via GitHub and AI Search Results
Cybersecurity researchers have uncovered a campaign distributing malware through fake installers for OpenClaw, a popular AI agent platform. The attack leveraged both GitHub hosting and AI-generated search results to increase credibility and…
-
Google Begins Quantum Safe Upgrade for HTTPS
Google is developing a new technical approach designed to help keep secure websites protected as computing technology evolves. HTTPS is the security system that protects information sent between a user’s browser and…
-
Research Finds Critical Flaws in Wi-Fi Client Isolation
New academic research reveals that a core Wi-Fi security feature relied upon by home, enterprise, and public networks can be bypassed in practice — even when modern encryption is enabled. The study,…
-
Claude Code Vulnerabilities Expose Developers to Silent Code Repository Attacks
Recent research by Check Point Research has uncovered critical vulnerabilities in Anthropic’s Claude Code, highlighting a growing and often overlooked risk in modern AI-powered development tools: configuration files that quietly cross the…
-
Cyberattacks Using Routine Actions to Exploit Trust
Security researchers are increasingly warning that cyberattacks no longer rely on obvious malware or suspicious downloads. Instead, many modern campaigns succeed by blending into routine, trusted workflows, the everyday actions people perform…
-
CarGurus Breach Impacts 12M+ Accounts
Have I Been Pwned, a security service website, has added CarGurus to its data breach database, confirming that the automotive marketplace was impacted by a data leak affecting over 12 million accounts.…
-
SolarWinds Serv-U 15.5.4 Fixes Four Critical RCE Vulnerabilities
SolarWinds has released Serv-U 15.5.4 with patches for multiple critical vulnerabilities as well as feature parity improvements in File Share amongst other updates. Serv-U is commonly deployed in managed file transfer contexts,…
