Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, include a critical authentication bypass in WPMU DEV Dashboard, stored XSS in Avada, SQL injection in TranslatePress, PHP object injection in Pods, and an authentication bypass in GiveWP. Users are strongly advised to update all affected plugins and themes immediately to prevent potential site takeovers and remote code execution.
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service.
In this article Attack chain overview Mitigation and protection guidance Learn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.
Businesses are adopting AI rapidly but often overlook security implications. This virtual event guides enterprise leaders on building a robust security framework for AI systems, covering threat modeling, data integrity, and regulatory compliance to prevent model poisoning and data breaches.
As AI workloads shift to the cloud, traditional security approaches fall short. This virtual event focuses on protecting cloud assets in an AI era, emphasizing identity management, encryption, and real-time threat detection to safeguard against data exfiltration and unauthorized access.
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.