CISA Warns of Gitea Code Injection Vulnerability Exploited in Attacks

2 days ago

The Cybersecurity and Infrastructure Security Agency has added a newly disclosed Gitea vulnerability to its Known Exploited Vulnerabilities catalog, confirming…

21 Critical Ubiquiti UniFi Flaws Enable Authentication Bypass, Command Injection and Privilege Escalation

2 days ago

Ubiquiti has patched 21 critical-severity vulnerabilities spanning nearly its entire UniFi product line, warning that attackers with only network access…

Critical Next.js Vulnerabilities Enables Remote Code Execution Attacks

2 days ago

Two critical Next.js flaws allow unauthenticated remote code execution on Windows-hosted applications using the Image Optimization API to process AVIF…

OpenAI Bans Russia-Linked ChatGPT Accounts Used in Covert Influence Campaign

2 days ago

OpenAI has removed a cluster of ChatGPT accounts linked to a covert influence operation from Russia. The accounts produced social-media…

Iran-Linked Hackers Expand Attacks With New Backdoor and Reverse SSH Tunnels

2 days ago

Iran-linked hackers have expanded an espionage effort with a Windows backdoor and reverse SSH tunnelling utility. The activity is tied…

Hackers Use Fake Claude Desktop App to Disable Defender and Install Remote Access Malware

2 days ago

Cybercriminals are using a counterfeit Claude desktop application to compromise Windows systems, disable key security checks, and install remote-access malware.…

24 Malicious npm Packages Abuse Trusted Mirrors to Host ClickFix Phishing Pages

2 days ago

Twenty-four malicious npm packages have been used to turn trusted package mirrors into staging points for ClickFix phishing pages. The…

Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access

2 days ago

A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems. The…

SonicWall NetExtender Vulnerabilities Allow an Attacker to Write Arbitrary Files as Root

2 days ago

SonicWall has disclosed two security vulnerabilities in its NetExtender Linux client, including a critical path traversal flaw that could allow…

WordPress Plugin Vulnerability Exposes 400,000 Sites to Account Takeover Attacks

2 days ago

A critical vulnerability in the TranslatePress WordPress plugin could allow unauthenticated attackers to hijack administrator accounts and fully compromise affected…