Latest Briefings
Attackers Exploit WooCommerce Plugin Flaw to Plant PHP Web Shells
A critical unauthenticated file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited to drop PHP backdoors on WordPress…
CISA Confirms Active Exploitation of Max-Severity GitLab Flaw
Attackers are exploiting a critical unauthenticated path traversal bug in GitLab's repository commits API just days after a patch shipped, prompting CISA…
China-Linked Hackers Exploit Sogou Input Method Flaw to Drop GrayRabbit Backdoor
A one-click RCE bug in Tencent's Sogou Input Method for Windows let the UNC3569 threat group chain three flaws into full code…
BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days Across Espionage Groups
Proofpoint says a newly discovered exploit kit combining two Chrome V8 zero-days and a Windows ALPC privilege escalation flaw was rapidly adopted…
Dutch NCSC Warns of Imminent Attacks on Critical Check Point VPN Flaws
Two unauthenticated remote code execution bugs in Check Point's VPN stack have patches available, and the Netherlands' national cyber agency says exploitation…
Cisco FMC Bugs Exploited by Qilin Ransomware and Sandworm-Linked Hackers
Cisco Talos says three separate threat clusters, including ransomware affiliates and a group overlapping with the Russian Sandworm APT, exploited two Secure…
CISA Flags Active Exploits in JFrog and ConnectWise as GitLab Rushes Critical Patch
CISA added three actively exploited flaws in JFrog Artifactory and ConnectWise ScreenConnect to its KEV catalog, while GitLab pushed emergency fixes for…
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes, including one authentication bypass flaw scoring…
Critical GiveWP Flaw Lets Unauthenticated Attackers Run Server Commands
A maximum-severity vulnerability in the popular GiveWP WordPress donation plugin lets attackers register accounts even when signups are disabled, then chain that…
Cosmos EVM Balance Flaw Exploited Across Six Chains After Cosmos Labs Knew Risk Existed
A critical balance-handling bug in the shared Cosmos EVM module was used to drain funds from six blockchains over five days in…
PaperCut Zero-Day Under Active Exploitation, Hits All NG and MF Versions
PaperCut has confirmed active zero-day attacks against all versions of its NG and MF print management software, releasing emergency patches while urging…
Critical Avada WordPress Theme Flaw Chains Six Bugs Into Zero-Click RCE
A critical vulnerability chain in the Avada theme and Fusion Builder plugin lets unauthenticated attackers achieve full server compromise, though exploitation requires…