Critical RCE flaw in Windows IKE Extension now actively exploited

Critical Windows Flaw Exploited in the Wild, CISA Warns A critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component is being actively exploited by hackers. This means that anyone can send malicious packets to an unpatched Windows system, potentially allowing attackers to gain control of it. The vulnerability, … Read more

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Cybersecurity threat actors have been exploiting a previously unknown vulnerability in Windchill, a widely used product lifecycle management (PLM) software, according to a recent discovery. The issue, linked to the notorious Clop ransomware group, allows attackers to decrypt sensitive engineering data and gain unauthorized access to credentials. The vulnerable software, owned by PTC Inc., is … Read more

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

A sprawling cybercrime operation has been uncovered, with Microsoft linking over 30 rotating domains to a notorious malware infrastructure known as MacSync Stealer. This sophisticated threat affects users across multiple platforms, exploiting vulnerabilities in identity exposure and privilege escalation to unleash devastating attacks on unsuspecting victims. At the heart of this operation lies a cleverly … Read more

GitLab Patches Critical Code Injection Vulnerability

GitLab has issued patches for two critical vulnerabilities that can be exploited without authentication, allowing attackers to manipulate user data and public projects. The company’s Community Edition (CE) and Enterprise Edition (EE) users from version 18.2 onwards are impacted. The first vulnerability, tracked as CVE-2026-19478 with a CVSS score of 9.4, allows an unauthenticated attacker … Read more

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Over 300,000 WordPress sites are potentially exposed to hacking due to a critical vulnerability in the Forminator Forms plugin, which allows attackers to upload executable files and execute code remotely. This means that thousands of websites could be compromised, leading to site takeover and data theft. The issue, tracked as CVE-2026-15748 with a CVSS score … Read more

CareCloud Data Breach Impact Grows to 3.7 Million Individuals

A massive data breach at cloud-based healthcare solutions provider CareCloud has exposed the sensitive information of over 3.7 million individuals, a staggering increase from initial reports that put the number affected at around 350,000. The breach, which was first detected in mid-March and publicly disclosed by CareCloud in early July, is believed to have occurred … Read more

CISA: Medusa ransomware hit over 500 critical infrastructure orgs

A Devastating Wave of Ransomware Attacks Hits Over 500 Critical Infrastructure Organizations The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. This staggering number was disclosed in a joint advisory issued by CISA, the Federal … Read more

GitLab Patches Critical Code Injection Vulnerability

A critical code injection vulnerability has been patched in GitLab, a popular platform for code management and sharing. The flaw, tracked as CVE-2026-19478, allows attackers to modify or delete user data and public projects without needing authentication. The security defect was discovered through GitLab’s HackerOne bug bounty program and affects all versions of the GitLab … Read more

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Over 300,000 WordPress Sites Left Exposed to Hacking Due to Critical Plugin Flaw A critical vulnerability in the Forminator Forms plugin for WordPress has potentially exposed thousands of websites to remote code execution (RCE), according to security firm Defiant. The bug, tracked as CVE-2026-15748 with a CVSS score of 9.8, allows unauthenticated attackers to upload … Read more