Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The WP2Shell attack chain exploits two vulnerabilities — CVE-2026-0098 and CVE-2026-03102 — to compromise millions of WordPress sites with remote code execution capabilities. By chaining these flaws, attackers can bypass authentication, upload arbitrary files, and execute PHP code on vulnerable WordPress installations without needing valid credentials.
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages, but cost and human-in-the-loop viability remain open questions.
Ivanti's CSO reports that frontier LLMs show surprising effectiveness at generating security patches for identified vulnerabilities, potentially transforming vulnerability remediation from a bottleneck into an automated process. The models can analyze vulnerable code, understand the nature of the flaw, and produce syntactically correct patches that address the root cause without introducing regressions.
Twenty-five years after the Code Red worm crashed through the internet, Marc Maiffret, one of the vulnerability researchers who analyzed the outbreak, reflects on its legacy and the lessons it holds for today's security landscape. Code Red demonstrated how a single worm exploiting a buffer overflow in Microsoft IIS could spread globally within hours, causing billions in damage and foreshadowing the automated, self-propagating attacks that dominate modern threat landscapes.
Twenty-five years after the Code Red worm crashed through the internet, Marc Maiffret, one of the vulnerability researchers who analyzed the outbreak, reflects on its legacy and the lessons it holds for today's security landscape. Code Red demonstrated how a single worm exploiting a buffer overflow in Microsoft IIS could spread globally within hours, causing billions in damage and foreshadowing the automated, self-propagating attacks that dominate modern threat landscapes.
CISOs are feeling increased job pressure as organizations rush to adopt AI technologies without fully understanding the associated security risks. Security leaders find themselves in the difficult position of either supporting rapid AI deployment — potentially exposing the organization to data leakage, model poisoning, or compliance violations — or slowing adoption and being seen as obstructing innovation.