Key takeaways WordPress shipped an emergency security release, 7.0.3, on 6 August. The headline flaw is a scripting vulnerability on the login screen that needs no account to trigger. Researchers demonstrated a chain from that flaw to code execution on the server, but the chain needs a logged-in administrator to interact with an attacker-controlled page. […]
Read MoreKey takeaways Metabase has confirmed a maximum-severity flaw in its business intelligence platform was exploited as a zero-day, first against its own hosted service. An unauthenticated attacker could reach administrator access, then take the stored credentials for every database the tool connects to. The flaw scores 10.0, the highest possible rating, and has no CVE […]
Read MoreKey takeaways A CVE record is an identifier and a description. It is not, on its own, a judgement about how urgent the vulnerability is for you. CVSS answers how bad exploitation would be, EPSS answers how likely exploitation is in the next 30 days, and CISA’s KEV catalog answers whether exploitation has actually been […]
Read More