AI girlfriend review site's secrets were exposed to the world for three weeks A website reviewing AI girlfriends suffered a three-week security breach, exposing sensitive data. The vulnerability stemmed from a flaw in the website's code, allowing attackers to access user information. This highlights the ongoing need for rigorous security testing and vulnerability patching across all web applicat… The Register · 2d ago Medium vulnerabilityweb-securitydata-breach
threat-intel All-Line Equipment Company Fuel-Boss A vulnerability exists in All-Line Equipment Company's Fuel-Boss industrial control system software, specifically versions up to and including PHP 7.1.5. Exploitation could allow remote code execution by injecting a mali… CISA Advisories · 3d ago High CVE-2018-19518CVE-2019-11043industrial control systemscve-2018-19518cve-2019-11043
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
vulnerability Multiples vulnérabilités dans PHP (31 juillet 2026) Multiple vulnerabilities have been discovered in PHP versions 8.2, 8.3, 8.4, and 8.5, including SQL injection and denial of service attacks. Users are strongly advised to apply the security updates released by PHP’s publ… CERT-FR · Jul 31, 2026 Medium CVE-2026-17543CVE-2026-17544CVE-2026-7260phpvulnerabilitysql injection
vulnerability CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution CISA has added a critical vulnerability, CVE-2026-48907, to its Known Exploited Vulnerabilities catalog affecting the Widget Factory Joomla Content Editor (JCE) due to improper access control. This flaw allows for PHP co… The Hacker News · Jun 17, 2026 Critical CVE-2026-48907TUjoomlaphpcode execution
vulnerability CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability, CVE-2026-45247, affecting the Mirasvit Cache Warmer Magento extension to its KEV catalog. This flaw allows for remote c… The Hacker News · Jun 4, 2026 Critical CVE-2026-45247USUKFRphpobjectdeserialization
malware Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting Laravel Lang localization packages has resulted in attackers injecting credential-stealing malware through manipulated GitHub tags. The malicious code, disguised as legitimate releases, do… BleepingComputer · May 23, 2026 High USsupply chaincredential theftgithub
supply-chain Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A coordinated supply chain attack targeting the Packagist repository has compromised eight PHP packages, inserting malicious code into their package.json files. The attack leveraged GitHub Releases URLs to deploy a Linux… The Hacker News · May 23, 2026 High supply-chainphpcomposer
supply-chain Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer A sophisticated supply chain attack targeting Laravel-Lang PHP packages has been identified, involving the mass modification of Git tags to inject a cross-platform credential-stealing framework. The attacker leveraged co… The Hacker News · May 23, 2026 Critical USsupply-chaincredential-stealingphp
threat-intel Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare Drupal has announced an upcoming core security release scheduled for May 20, 2026, urging users to prepare and update their systems proactively. The release addresses potential vulnerabilities that could be exploited qui… The Hacker News · May 19, 2026 High drupalsecurityupdate