WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Breaches, offensive and defensive AI, and surveillance.
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Compromised credentials for third-party Ribon applications allowed attackers to inject malicious scripts into BigCommerce online stores.
A recognized but underappreciated flaw in LLM applications may let AI agents consume resources without limits, leading to severe financial damage.
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
A new npm campaign shows attackers can bypass supply-chain checks by triggering malicious behavior only when the package runs, not during installation.
Two sandbox escape techniques from OpenAI Codex, including one that ran commands on a developer's machine, have been patched.
A new analysis argues that organizations cannot secure identities they cannot see, pointing to stolen credentials as a leading breach entry point.
A newly disclosed attack technique, BragJack, exploits built-in browser AI assistants to steal data and execute malicious actions.
A viral AI video-call service collects facial and mood data from callers, raising privacy concerns before it shuts down.
The ShinyHunters extortion group has turned the tables on Clop by hacking and defacing the ransomware gang's own data leak site.
The cybersecurity startup has secured over $7 million in contracts with US Space Force, Navy, and DARPA.
Attackers are actively exploiting a critical unauthenticated remote code execution vulnerability in Orkes Conductor via inline workflow definitions.
The new partner program expands Vectra AI's ecosystem to meet rising demand for AI expertise and security services in increasingly complex environments.
A new EY survey of senior AI executives finds that organizations are rolling out autonomous systems faster than they are building the controls to oversee them.
A Friday squid essay becomes an unlikely venue for surfacing security stories that Schneier hasn't covered.
A CVSS 10.0 privilege escalation vulnerability in Azure AI Foundry was patched as part of a broader Microsoft security update.
Kaspersky reports that the hacking group NightEagle, previously tied to China's high-tech sector, has now been linked to incidents at Russian businesses.
Researchers warn of a new Android trojan that combines AI-driven device control with ADB-based persistence to survive uninstallation.