SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.

The hardware wallet maker said all affected cu… Continue reading SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

Posted in Uncategorized

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete publ… Continue reading Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Posted in Uncategorized

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.

The vulnerability, tracked as CVE-2026-1… Continue reading Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Posted in Uncategorized

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones.

This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromis… Continue reading ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

Posted in Uncategorized

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.

The advisory,… Continue reading Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Posted in Uncategorized