Category: Vulnerabilities
CenterPoint Energy Confirms Breach After Hacker Leaks 7.5M Customer Records
The Houston-based utility confirmed an unauthorized party accessed customer data through an external-facing system, days after a threat actor leaked an archive…
Japan’s Digital Agency: VPN Flaw Breach Exposed 246,000 Personnel Records
An attacker exploited a medium-severity, non-zero-day VPN vulnerability to access Japan's Government Solution Service, potentially exposing names, emails, phone numbers, and addresses…
Telus Notifies Customers of Account Takeovers Tied to Compromised Credentials
Canadian telecom giant Telus is warning consumer customers that attackers used stolen credentials to access accounts and personal data, then tried to…
CISA Confirms Active Exploitation of Max-Severity GitLab Flaw
Attackers are exploiting a critical unauthenticated path traversal bug in GitLab's repository commits API just days after a patch shipped, prompting CISA…
China-Linked Hackers Exploit Sogou Input Method Flaw to Drop GrayRabbit Backdoor
A one-click RCE bug in Tencent's Sogou Input Method for Windows let the UNC3569 threat group chain three flaws into full code…
Dutch NCSC Warns of Imminent Attacks on Critical Check Point VPN Flaws
Two unauthenticated remote code execution bugs in Check Point's VPN stack have patches available, and the Netherlands' national cyber agency says exploitation…
CISA Flags Active Exploits in JFrog and ConnectWise as GitLab Rushes Critical Patch
CISA added three actively exploited flaws in JFrog Artifactory and ConnectWise ScreenConnect to its KEV catalog, while GitLab pushed emergency fixes for…
Microsoft Says Ignore False ‘Antivirus Turned Off’ Alerts After Defender Update
A bug in recent Microsoft Defender Antivirus updates is triggering false alerts that protection is disabled across Windows client and server systems.…
FulcrumSec Claims Manchester Airports Breach, Says 86 GB of Data Stolen
Extortion group FulcrumSec has claimed responsibility for the Manchester Airports Group breach, telling BleepingComputer it exfiltrated 86 GB of data including detailed…
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Researchers at Wordfence and Patchstack have disclosed five critical vulnerabilities across popular WordPress plugins and themes, including one authentication bypass flaw scoring…
Critical GiveWP Flaw Lets Unauthenticated Attackers Run Server Commands
A maximum-severity vulnerability in the popular GiveWP WordPress donation plugin lets attackers register accounts even when signups are disabled, then chain that…
Cosmos EVM Balance Flaw Exploited Across Six Chains After Cosmos Labs Knew Risk Existed
A critical balance-handling bug in the shared Cosmos EVM module was used to drain funds from six blockchains over five days in…