Critical Forminator WordPress Flaw: What to Do Now

A critical flaw in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload executable PHP files to a vulnerable site. Tracked as CVE-2026-15748 and rated 9.8 on the CVSS scale, it was fixed in version 1.56.2 on 31 July 2026. Roughly half of installations were still running […]

Read More

Ransomware: a business leader’s risk brief

Key takeaways The ransom is the smaller number. Recovery now costs an average of US$1.7 million per incident before any ransom is counted, and that figure rose 11 percent in a year even as ransom demands fell. The entry point has moved. For the first time in four years, exploited vulnerabilities are not the leading […]

Read More

Microsoft’s November 2025 Security Update: What You Need to Know

Microsoft’s November 2025 Patch Tuesday fixes 63 security flaws across Windows, Office, .NET, and developer tools, five of them rated critical. The most urgent is an actively exploited Windows Kernel zero-day, CVE-2025-62215, which attackers are already using to gain full control of affected machines. The single most important action, for home users and businesses alike, […]

Read More