
Cyber Attacks
View all
Inexpensive Androids Come With Midnight Mimosa Firmware Bug for Ad Fraud
Hackread and BleepingComputer report that cheap Android smartphones ship with pre-installed firmware malware enabling ad fraud and proxy abuse before users power on.
Cloud Security
View allVulnerabilities
View all
Travesia WordPress Theme CWE-502 Deserialization Vulnerability CVE-2026-93929 Hits v1.1.16 and Older
A critical object injection vulnerability in the Travesia WordPress theme allows untrusted data deserialization, affecting versions through 1.1.16 with a CVSS score of 9.8.

TOZED X300 IPPingDiagnostics Handler Vulnerable to Remote OS Command Injection
Unpatched OS command injection in TOZED X300 firmware allows remote attackers to execute arbitrary commands via manipulated ping arguments.

Wukong_HRM ParamAspect Auth Bypass CVE-2026-108707 Risks Remote HR Data Manipulation and Deletion
A critical flaw in the ParamAspect component allows unauthenticated users to access all HR API endpoints by omitting a specific header.

SiteVault 1.5.19: Code Injection Flaw Enables Critical Unauthenticated Remote Code Execution
Royal Plugins SiteVault plugin allows unauthenticated remote code execution in versions up to 1.5.19, rated critical by NVD.
Data Breaches
View all
Unprotected Internet-Facing Interfaces at 8,547 Global Renewable Sites Enable Remote Turbine Control

How Breach Notification Letters Work: The Hidden Mechanics

How to Stop Source Code Leaks Before They Happen

Stop Unauthorized Access: Practical Controls That Actually Work
Latest news
Malware & Ransomware
Zero Day Malware: How It Works and How to Contain It
Zero day malware exploits unknown vulnerabilities before patches exist, making signature-based detection useless and forcing reliance on behaviour analysis.
Threat Intelligence
Detection Engineering Lifecycle: Build, Tune and Maintain Alerts
Detection engineering transforms raw telemetry into reliable signals by treating alerts as code that requires continuous validation and iterative refinement.
Vulnerabilities
Tonda Membership Plugin Critical Auth Bypass Lets Attackers Gain Admin Access Without Credentials
Select-Themes plugin allows attackers to gain administrative access without credentials, rated 9.8 CVSS.
Vulnerabilities
Out-of-band patches: what small businesses need to know
Emergency updates bypass standard testing cycles, creating a high risk of system instability if applied without rigorous validation procedures.
Vulnerabilities
AhsayCBS Backup Platform Vulnerabilities Exploited for Webshell and Miner Deployment
Threat actors are actively exploiting unpatched flaws in the AhsayCBS backup management platform to install webshells and cryptocurrency mining software.
Vulnerabilities
AWS Ops Wheel flaws CVE-2026-6911 and CVE-2026-6912 expose infrastructure configs
Two security issues in AWS Ops Wheel allow potential exposure of sensitive cloud infrastructure configurations to unauthorized users.
Vulnerabilities
Gutentype Object Injection: Critical Deserialization of Untrusted Data Affects Versions Through 2.1.12
The National Vulnerability Database rates CVE-2026-62046 as critical, warning that untrusted data handling in the Gutentype plugin enables object injection.
Vulnerabilities
Convex Plugin Deserialization Vulnerability Enables Remote Object Injection on WordPress Sites
Deserialization of untrusted data in the Convex plugin exposes WordPress sites to remote object injection attacks requiring immediate attention.







