Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.

“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary fil… Continue reading Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Posted in Uncategorized

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether what … Continue reading DeepZero: Open-source hunting for vulnerable Windows drivers

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.

The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographi… Continue reading Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Posted in Uncategorized

The modern attack chain: Rethinking Google Workspace security in the age of AI

Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren’t isolated incide… Continue reading The modern attack chain: Rethinking Google Workspace security in the age of AI

MSPs say nearly half their customers rely on them for CISO services

MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the work across several tools. Most providers exp… Continue reading MSPs say nearly half their customers rely on them for CISO services

Ubuntu’s ‘Rust-ification’ Hits New Milestone: Coreutils Migration is Complete

“Ubuntu has managed to do away with GNU Core Utilities in its default stack,” reports the blog It’s FOSS.

The last three utilities — cp, mv and rm — have been moved to versions from the uutils project (which reimplements utilities in Rus… Continue reading Ubuntu’s ‘Rust-ification’ Hits New Milestone: Coreutils Migration is Complete