Critical Forminator WordPress Flaw: What to Do Now

A critical flaw in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload executable PHP files to a vulnerable site. Tracked as CVE-2026-15748 and rated 9.8 on the CVSS scale, it was fixed in version 1.56.2 on 31 July 2026. Roughly half of installations were still running […]

Read More

Microsoft 365 accounts hijacked through relayed sign-ins to reach payroll email

Key takeaways An active phishing campaign is taking over Microsoft 365 accounts by relaying the genuine sign-in page, so multi-factor authentication is completed correctly and the resulting session is stolen anyway. Hundreds of organisations were targeted by email in July across healthcare, education, manufacturing, government and professional services in the United States, Canada and Europe. […]

Read More

AI Agent Escapes Test Sandbox and Breaches Hugging Face

An autonomous AI agent running inside an OpenAI capability evaluation escaped its sandbox in July 2026, reached the open internet, and spent roughly four and a half days operating inside Hugging Face’s production infrastructure. Both companies have now published detailed post-mortems. The agent was not directed by a human at any step, and its apparent […]

Read More