Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A Critical WordPress Flaw Exposes Sites to Remote Code Execution Attacks A severe vulnerability in Forminator, a popular WordPress plugin used by millions of websites, has been disclosed. The flaw allows attackers to execute arbitrary code on affected sites without authentication, potentially leading to data breaches and complete website takeover. This critical weakness is particularly … Read more

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

A critical vulnerability in GitHub Actions has been discovered, allowing attackers to inject malicious commands on vulnerable repositories. The flaw, found by a security researcher, lets hackers create specially crafted issues that can exploit a weakness in the way GitHub processes user input. This vulnerability affects all users of GitHub’s issue-tracking feature and poses a … Read more

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Critical GitLab GraphQL Flaw Exposes Public Projects to Deletion by Unauthenticated Attackers A serious vulnerability in the GitLab platform’s GraphQL API has been discovered, allowing unauthenticated attackers to delete public projects. The flaw affects all GitLab instances that have the GraphQL feature enabled, making it a widespread issue that requires immediate attention from users and … Read more

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center Suffers Data Breach Exposing Customer Information and Canceling Orders In a concerning development, Pokémon Center has announced that it has suffered a data breach after hackers targeted its third-party logistics provider, CEVA Logistics. The incident has exposed customer personal and order information for customers in the United Kingdom and Germany, prompting the company … Read more

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

A sophisticated threat actor has been using a novel technique called Cavern C2 to blend malicious activity with legitimate traffic, evading detection by security systems. This clever tactic leverages Google Apps Script and DNS to create an almost undetectable attack path, putting countless organizations at risk. Cavern C2 works by utilizing Google’s cloud infrastructure to … Read more

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A Critical Flaw in Forminator WordPress Plugin Exposes Sites to Remote Code Execution Attacks A severe vulnerability has been discovered in the popular Forminator plugin for WordPress, which allows attackers to execute arbitrary code on affected websites without authentication. The critical flaw, uncovered by security researchers, can be exploited via malicious PHP uploads, putting hundreds … Read more

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

A Critical GitHub Actions Flaw Exposes Developers to Command Injection Attacks A severe vulnerability has been discovered in GitHub’s Actions feature, which allows maliciously crafted issues to trigger command injection attacks against developers’ repositories. The flaw, identified by a researcher, enables an attacker to inject arbitrary system commands into affected projects, giving them elevated privileges … Read more

French tax authority data breach affects 678,000 individuals

A massive data breach at the French tax authority has left 678,000 individuals exposed, with sensitive financial and personal information potentially compromised. The attack, which was announced on August 12, is just the latest in a string of cyberattacks to hit French government agencies this year. According to the French Finance Ministry, an attacker using … Read more

Philips and GE investigating Clop ransomware data theft claims

Two Tech Giants and an Oil Giant Investigate Claims of Clop Ransomware Data Theft A trio of high-profile companies is facing a potentially serious cybersecurity breach after the notorious Clop ransomware gang claimed to have stolen sensitive data from their systems. General Electric (GE), Philips, and Shell are all investigating claims that the attackers exploited … Read more