A critical flaw in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload executable PHP files to a vulnerable site. Tracked as CVE-2026-15748 and rated 9.8 on the CVSS scale, it was fixed in version 1.56.2 on 31 July 2026. Roughly half of installations were still running […]
Read MoreGeoServer has shipped emergency releases for a critical SQL injection flaw that its own maintainers describe as a regression of a vulnerability fixed in 2023. The flaw was disclosed publicly on X on 12 August with no vendor coordination, drew scanning within hours, and was patched on 14 August. It still has no CVE identifier, […]
Read MoreKey takeaways “Endpoint” is industry shorthand for a device someone actually uses: a phone, a laptop, a tablet, a desktop. Attacks on personal devices now mostly aim to quietly copy what is already signed in, not to break anything you would notice. Most of the protection you need is already built into your device and […]
Read MoreKey takeaways Sri Lanka CERT has warned iPhone users about WhatsApp account takeovers requiring no action from the victim, following reports from people in the media and business communities. Victims describe messages sent from their account asking contacts for money, with nothing showing under Linked Devices, and in some cases loss of control of groups […]
Read MoreKey takeaways WordPress shipped an emergency security release, 7.0.3, on 6 August. The headline flaw is a scripting vulnerability on the login screen that needs no account to trigger. Researchers demonstrated a chain from that flaw to code execution on the server, but the chain needs a logged-in administrator to interact with an attacker-controlled page. […]
Read MoreKey takeaways Metabase has confirmed a maximum-severity flaw in its business intelligence platform was exploited as a zero-day, first against its own hosted service. An unauthenticated attacker could reach administrator access, then take the stored credentials for every database the tool connects to. The flaw scores 10.0, the highest possible rating, and has no CVE […]
Read MoreKey takeaways The ransom is the smaller number. Recovery now costs an average of US$1.7 million per incident before any ransom is counted, and that figure rose 11 percent in a year even as ransom demands fell. The entry point has moved. For the first time in four years, exploited vulnerabilities are not the leading […]
Read MoreKey takeaways The research released around Black Hat USA 2026 agrees on one thing: AI has compressed attacker timelines, but the way intruders get in has not changed. Phishing was the initial access method in more than half of Cisco Talos incident response engagements last quarter, and authentication abuse appeared in 65 percent of them. […]
Read MoreMicrosoft’s November 2025 Patch Tuesday fixes 63 security flaws across Windows, Office, .NET, and developer tools, five of them rated critical. The most urgent is an actively exploited Windows Kernel zero-day, CVE-2025-62215, which attackers are already using to gain full control of affected machines. The single most important action, for home users and businesses alike, […]
Read More