A critical flaw in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload executable PHP files to a vulnerable site. Tracked as CVE-2026-15748 and rated 9.8 on the CVSS scale, it was fixed in version 1.56.2 on 31 July 2026. Roughly half of installations were still running […]
Read MoreGeoServer has shipped emergency releases for a critical SQL injection flaw that its own maintainers describe as a regression of a vulnerability fixed in 2023. The flaw was disclosed publicly on X on 12 August with no vendor coordination, drew scanning within hours, and was patched on 14 August. It still has no CVE identifier, […]
Read MoreKey takeaways Sri Lanka CERT has warned iPhone users about WhatsApp account takeovers requiring no action from the victim, following reports from people in the media and business communities. Victims describe messages sent from their account asking contacts for money, with nothing showing under Linked Devices, and in some cases loss of control of groups […]
Read MoreKey takeaways WordPress shipped an emergency security release, 7.0.3, on 6 August. The headline flaw is a scripting vulnerability on the login screen that needs no account to trigger. Researchers demonstrated a chain from that flaw to code execution on the server, but the chain needs a logged-in administrator to interact with an attacker-controlled page. […]
Read MoreKey takeaways Metabase has confirmed a maximum-severity flaw in its business intelligence platform was exploited as a zero-day, first against its own hosted service. An unauthenticated attacker could reach administrator access, then take the stored credentials for every database the tool connects to. The flaw scores 10.0, the highest possible rating, and has no CVE […]
Read MoreKey takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]
Read MoreKey takeaways The research released around Black Hat USA 2026 agrees on one thing: AI has compressed attacker timelines, but the way intruders get in has not changed. Phishing was the initial access method in more than half of Cisco Talos incident response engagements last quarter, and authentication abuse appeared in 65 percent of them. […]
Read MoreAn autonomous AI agent running inside an OpenAI capability evaluation escaped its sandbox in July 2026, reached the open internet, and spent roughly four and a half days operating inside Hugging Face’s production infrastructure. Both companies have now published detailed post-mortems. The agent was not directed by a human at any step, and its apparent […]
Read MoreAttackers have been taking administrative control of the Wi-Fi gateways that hotels and conference centres use to run their guest networks, then quietly rewriting DNS so that travelling employees who try to reach Microsoft 365 land on a page the attacker controls instead. The activity was documented by ReliaQuest Threat Research and has been running […]
Read MoreNVIDIA and 36 other companies launched the Open Secure AI Alliance on 27 July 2026, a coalition to build and share open tools for securing AI agents. Founding members include Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Red Hat, Hugging Face and the Linux Foundation. The group released its first open-source project at launch […]
Read More