Cybersecurity

WP Maps Pro Flaw Lets Attackers Create Admin Accounts

A critical vulnerability (CVE-2026-8732) in the WP Maps Pro WordPress plugin allows attackers to create admin accounts.The flaw affects versions prior to 6.1.1 and...

Dutch Police Shut Down Massive 17-Million Device Botnet

Dutch authorities dismantled a massive botnet of at least 17 million infected devices.The botnet's backend infrastructure included over 200 servers based in the Netherlands.The...

LLM Agent Exploits Marimo Vulnerability, Steals Database

A threat actor used an LLM agent to automate post-exploitation actions after breaching a public-facing Marimo notebook via the critical CVE-2026-39987 vulnerability.The automated agent...

Critical RCE Flaw Found in Gogs Git Service

A critical, unpatched security flaw in the open-source Git service Gogs allows authenticated users to execute arbitrary code on the server.The vulnerability, rated 9.4...

Microsoft Urges Coordinated Disclosure After Zero-Day Flap

Microsoft advocates for Coordinated Vulnerability Disclosure (CVD) following the uncoordinated public release of multiple Windows zero-days.A researcher disclosed six high-severity vulnerabilities, including three already...

Cryptocriminal JINX-0164 Targets Macs in Sophisticated Supply Chain Heist

A new financially motivated threat actor, tracked as JINX-0164, is actively targeting cryptocurrency organizations with sophisticated social engineering and custom macOS malware.The campaign uses...

New npm Malware Steals Claude AI User Data

A new malicious npm package, "mouse5212-super-formatter," steals files from the Claude AI tool's dedicated upload directory.The malware uploads stolen data to a threat actor-controlled...

GlassWorm Botnet Disrupted After Targeting Devs

Major cybersecurity firms CrowdStrike, Google, and Shadowserver Foundation disrupted a persistent developer-targeting botnet named GlassWorm on May 27, 2026.The botnet used trojanized VS Code...

Latest news

Israel’s Crypto Amnesty Fails To Meet Tax Goals

The Israel Tax Authority's voluntary disclosure policy for crypto taxes has yielded far less revenue than the expected $1...

Gemini AI Hijacked Via Fake Android Notifications

A researcher bypassed Google’s security updates for its Gemini voice assistant on Android using a technique called Fake Context...

Broadcom Stock Rises Ahead of Earnings Expected to Beat

Broadcom stock hit a new intraday high ahead of its earnings report, with analysts expecting it to beat Wall...