vulnerability Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant… The Hacker News · 1d ago Critical CVE-2026-76581CVE-2026-18431CVE-2026-19632wordpressvulnerabilityplugin
threat-intel Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers Google announced a significant privacy update for Android 17, introducing Encrypted Client Hello (ECH) to prevent network providers from tracking users' website visits. This feature is being rolled out alongside Local Ne… The Hacker News · 2d ago Medium privacynetworksecurity
threat-intel 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code A cluster of 18 Google Chrome and 1 Microsoft Edge extensions, some purchased and others created by the threat actor, have been discovered harboring wallet-stealing and cryptocurrency-draining capabilities. The campaign,… The Hacker News · 2d ago High extensionmalwarewallet
threat-intel Australian cops cuff alleged TeamPCP masterminds This article covers a range of cybersecurity and technology news stories, including a takedown of Iranian propaganda sites, a security patch for a vulnerable SharePoint instance, and a report on Joomla extension vulnerab… The Register · 2d ago Medium IRsecuritycybersecurityj2ee
threat-intel CRPx0 hacking service for dummies claims victim count more than quintupled This article reports on a hacking service claiming to have significantly increased its victim count, likely related to exploiting vulnerabilities in software and websites. The service is targeting Joomla websites and pot… The Register · 2d ago Medium vulnerabilityjoomlaextension
AI girlfriend review site's secrets were exposed to the world for three weeks A website reviewing AI girlfriends suffered a three-week security breach, exposing sensitive data. The vulnerability stemmed from a flaw in the website's code, allowing attackers to access user information. This highligh… The Register · 2d ago Medium vulnerabilityweb-securitydata-breach
threat-intel ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories This week’s ThreatsDay bulletin highlights a diverse range of cyber threats, including a 296,000-device IoT botnet, social engineering attacks targeting security teams, and a growing number of credential-stealing malware… The Hacker News · 3d ago High CVE-2026-55040CVE-2026-63520RUsocial engineeringphishingcredential theft
threat-intel Cybercrooks jet off with Manchester Airports Group customer data Russian cybercriminals are leveraging social engineering tactics, impersonating Signal support, to conduct phishing attacks targeting individuals and potentially stealing sensitive data. Simultaneously, vulnerabilities i… The Register · 3d ago High RUphishingjoomlavulnerability
threat-intel JavaScript obfuscation: From party trick to phishing kit This article from Cisco Talos explores the techniques used to obfuscate JavaScript code, primarily for malicious purposes like phishing and malware delivery. The author details various methods of hiding code, including s… Cisco Talos · 3d ago High obfuscationjavascriptmalware
threat-intel OpenAI explains how its AI agents did crime and attacked Hugging Face This article doesn't present a specific security incident but rather highlights a broader trend of security vulnerabilities and exploits within open-source software and related technologies. It touches on themes of open-… The Register · 3d ago Medium vulnerabilityopen-sourceexploit
threat-intel 58 arrested in international cybercrime crackdown Interpol and law enforcement agencies across 22 countries concluded Operation Jackal IV, resulting in the arrest of 58 individuals involved in a coordinated cybercrime operation. The operation targeted a crime-as-a-servi… The Record · 4d ago High ARITROcybercrimeromance scamsmoney laundering
vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and g… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
threat-intel E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with net… The Hacker News · 5d ago High UNdvrftpremote access trojan
vulnerability CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw CISA has issued a critical three-day patch deadline for a vulnerability in the Perfect 10 plugin for Joomla, which is being actively exploited by attackers. This plugin flaw allows attackers to gain unauthorized access t… The Register · 5d ago Critical CVE-2026-21962joomlavulnerabilityplugin
threat-intel Crooks push Mac malware through fake OpenAI Codex ads Russian threat actors are leveraging fake OpenAI Codex advertisements to distribute malware targeting macOS users. The campaign uses a malicious installer disguised as a legitimate tool, aiming to compromise systems and… The Register · 5d ago Medium RUmacphishingmalware
vulnerability Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks A vulnerability in Joomla extensions, specifically iCagenda and Balbooa Forms, is being exploited by attackers to compromise websites running on vulnerable CMS platforms. This allows attackers to gain unauthorized access… The Register · 5d ago Medium joomlaextensionvulnerability
threat-intel Security vets rally around $4 paper password books for sale in Australia This article is a collection of snippets from The Register, covering a range of cybersecurity and technology news. It highlights a vulnerability impacting Joomla websites through exploited extensions, a Microsoft SharePo… The Register · 6d ago Medium CHvulnerabilityphishingransomware
threat-intel Chess.com : un nouveau pirate revendique 7,3 millions de profils A cybercriminal claims to have stolen a massive dataset from Chess.com, containing 7.3 million user profiles. The data includes email addresses, usernames, user IDs, and various profile details, representing a significan… ZATAZ · Aug 22, 2026 Medium data-breachscrapinguser-data
threat-intel AWS Security makes an inscrutable choice This article is a collection of security-related news snippets from The Register. It highlights a range of issues, including a phishing campaign impersonating Signal support, a zero-day vulnerability in on-prem SharePoin… The Register · Aug 21, 2026 Medium IRphishingzero-dayransomware
threat-intel New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets A new phishing toolkit, iAuthFlow V2, is leveraging passkeys to maintain access to accounts even after a password reset, highlighting a significant escalation in phishing tactics. The tool, sold for $10,000, utilizes a s… SecurityWeek · Aug 21, 2026 High phishingpasskeysocial engineering