LIVE FEED
Subscribe
//

Latest Briefings

Vulnerabilities Attackers Exploit WooCommerce Plugin Flaw to Plant PHP Web Shells
CRITICAL Vulnerabilities

Attackers Exploit WooCommerce Plugin Flaw to Plant PHP Web Shells

A critical unauthenticated file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited to drop PHP backdoors on WordPress…

by Robbie · 2 weeks ago
Vulnerabilities CISA Confirms Active Exploitation of Max-Severity GitLab Flaw
CRITICAL Vulnerabilities

CISA Confirms Active Exploitation of Max-Severity GitLab Flaw

Attackers are exploiting a critical unauthenticated path traversal bug in GitLab's repository commits API just days after a patch shipped, prompting CISA…

by Robbie · 2 weeks ago
Vulnerabilities China-Linked Hackers Exploit Sogou Input Method Flaw to Drop GrayRabbit Backdoor
CRITICAL Vulnerabilities

China-Linked Hackers Exploit Sogou Input Method Flaw to Drop GrayRabbit Backdoor

A one-click RCE bug in Tencent's Sogou Input Method for Windows let the UNC3569 threat group chain three flaws into full code…

by Robbie · 2 weeks ago
Exploits BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days Across Espionage Groups
CRITICAL Exploits

BlueMoon Exploit Kit Chains Chrome and Windows Zero-Days Across Espionage Groups

Proofpoint says a newly discovered exploit kit combining two Chrome V8 zero-days and a Windows ALPC privilege escalation flaw was rapidly adopted…

by Robbie · 2 weeks ago
Vulnerabilities Dutch NCSC Warns of Imminent Attacks on Critical Check Point VPN Flaws
CRITICAL Vulnerabilities

Dutch NCSC Warns of Imminent Attacks on Critical Check Point VPN Flaws

Two unauthenticated remote code execution bugs in Check Point's VPN stack have patches available, and the Netherlands' national cyber agency says exploitation…

by Robbie · 2 weeks ago
Exploits Cisco FMC Bugs Exploited by Qilin Ransomware and Sandworm-Linked Hackers
CRITICAL Exploits

Cisco FMC Bugs Exploited by Qilin Ransomware and Sandworm-Linked Hackers

Cisco Talos says three separate threat clusters, including ransomware affiliates and a group overlapping with the Russian Sandworm APT, exploited two Secure…

by Robbie · 2 weeks ago
Vulnerabilities CISA Flags Active Exploits in JFrog and ConnectWise as GitLab Rushes Critical Patch
CRITICAL Vulnerabilities

CISA Flags Active Exploits in JFrog and ConnectWise as GitLab Rushes Critical Patch

CISA added three actively exploited flaws in JFrog Artifactory and ConnectWise ScreenConnect to its KEV catalog, while GitLab pushed emergency fixes for…

by Robbie · 2 weeks ago
Vulnerabilities Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
CRITICAL Vulnerabilities

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes, including one authentication bypass flaw scoring…

by Robbie · 1 month ago
Vulnerabilities Critical GiveWP Flaw Lets Unauthenticated Attackers Run Server Commands
CRITICAL Vulnerabilities

Critical GiveWP Flaw Lets Unauthenticated Attackers Run Server Commands

A maximum-severity vulnerability in the popular GiveWP WordPress donation plugin lets attackers register accounts even when signups are disabled, then chain that…

by Robbie · 1 month ago
Vulnerabilities Cosmos EVM Balance Flaw Exploited Across Six Chains After Cosmos Labs Knew Risk Existed
CRITICAL Vulnerabilities

Cosmos EVM Balance Flaw Exploited Across Six Chains After Cosmos Labs Knew Risk Existed

A critical balance-handling bug in the shared Cosmos EVM module was used to drain funds from six blockchains over five days in…

by Robbie · 1 month ago
Vulnerabilities PaperCut Zero-Day Under Active Exploitation, Hits All NG and MF Versions
CRITICAL Vulnerabilities

PaperCut Zero-Day Under Active Exploitation, Hits All NG and MF Versions

PaperCut has confirmed active zero-day attacks against all versions of its NG and MF print management software, releasing emergency patches while urging…

by Robbie · 1 month ago
Vulnerabilities Critical Avada WordPress Theme Flaw Chains Six Bugs Into Zero-Click RCE
CRITICAL Vulnerabilities

Critical Avada WordPress Theme Flaw Chains Six Bugs Into Zero-Click RCE

A critical vulnerability chain in the Avada theme and Fusion Builder plugin lets unauthenticated attackers achieve full server compromise, though exploitation requires…

by Robbie · 1 month ago
1 2 3 … 10

THE 0600 BRIEF

Every critical CVE and AI-security story, in your inbox each morning.