vulnerability Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code Two unpatched vulnerabilities in Kaltura's HTML5 video player library (mwEmbed) allow remote attackers to read arbitrary files and execute code on a server, without requiring authentication. These flaws stem from unsafe deserialization and can be exploited even if the player is hosted on Kaltura's shared CDN infrastruc… The Hacker News · 4d ago High CVE-2026-19913CVE-2026-19912unpatcheddeserializationremote code execution
threat-intel 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages Researchers at OX Security discovered a campaign utilizing 24 npm packages to host fake Cloudflare CAPTCHA pages via unpkg mirrors, redirecting users to phishing infrastructure. The threat actors are leveraging npm's inf… The Hacker News · 5d ago High npmphishingmalware
threat-intel CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification Researchers have uncovered two denial-of-service (DoS) attacks exploiting how Content Delivery Networks (CDNs) handle HTTP/3 traffic, leading to significant amplification of requests and causing severe performance issues… The Hacker News · Aug 20, 2026 High CVE-2026-14456CHSIcdnddoshttp3
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
threat-intel Suspicious Polyfill login prompts pop up on Toshiba, Muji websites Toshiba and Muji websites were temporarily affected by malicious login prompts generated by the polyfill[.]io service, which injected malicious code into their scripts. The issue stemmed from the domain being acquired by… BleepingComputer · Jun 5, 2026 Medium JACHcdnjavascriptlogin
threat-intel Content Delivery Exploit Opens Websites to Brand Hijacking This article details a new exploit, dubbed "Underminr," that leverages vulnerabilities in Internet infrastructure to allow attackers to hijack websites and conceal malicious activity. The technique, a successor to domain… Dark Reading · May 21, 2026 High USEUCNcdndnsdomain fronting