WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

On some servers, that can go further, allowing the attacker to run their own code. The fix shipp… Continue reading WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers→

Posted in Uncategorized

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive d… Continue reading Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials→

Posted in Uncategorized

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”

The action, carried out with authorization from the U.S. District Court for … Continue reading Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises→

Posted in Uncategorized

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.

The flaw, tracked as… Continue reading Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials→

Posted in Uncategorized

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.

The tool, called BigDiskBuster, has no patch, no CVE, … Continue reading Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates→

Posted in Uncategorized

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.

The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no logi… Continue reading New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups→

Posted in Uncategorized

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.

The bug, tracked as CVE-2026-89775, allows a gues… Continue reading New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory→

Posted in Uncategorized

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Secur… Continue reading SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE→

Posted in Uncategorized