WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

A critical vulnerability in WordPress plugins is spreading rapidly across the web, with security researchers warning of a significant escalation in exploitation attempts. The issue, known as wp2shell, affects several popular plugins used by millions of websites, putting sensitive data at risk of exposure and exploitation. The root cause of this problem lies in a … Read more

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A newly discovered vulnerability in OpenSSL, known as “HollowByte,” has left a significant number of servers and applications at risk of being crippled by a denial-of-service (DoS) attack. The bug, identified by Okta’s red team, allows an attacker to exhaust a server’s memory before any security handshake can take place. The vulnerability arises from the … Read more

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

A pair of previously unknown vulnerabilities in SonicWall’s SMA1000 secure remote access appliances has allowed hackers to compromise sensitive systems and deliver custom malware, with the issue remaining unpatched for weeks before a fix was released. Cybersecurity firm Volexity revealed that the flaws were exploited by a threat actor known as UTA0533, which used the … Read more

Windows LegacyHive zero-day flaw gets free, unofficial patches

A recently disclosed Windows zero-day flaw has been patched by a cybersecurity company, even though Microsoft hasn’t yet released an official fix. The vulnerability, dubbed LegacyHive, allows attackers to escalate privileges on up-to-date Windows systems and gain automatic code execution when an admin account logs in. The issue was found by a security researcher using … Read more

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

A Critical Flaw in ServiceNow’s AI Platform Exposes Users to Unauthenticated Code Execution Risks, Leaving Organizations Scrambling to Secure Their Networks ServiceNow, a leading provider of cloud-based IT service management platforms, has recently disclosed a critical vulnerability in its AI-powered platform that allows attackers to execute arbitrary code without authentication. The flaw, discovered by researchers … Read more

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

A new strain of ransomware, dubbed ENCFORGE, has been discovered targeting artificial intelligence (AI) model files through a vulnerability in Langflow, a popular video editing software. This attack highlights the increasing sophistication of cyber threats and the need for organizations to prioritize AI-powered security measures. ENCFORGE leverages a remote code execution (RCE) flaw in Langflow, … Read more

Ernst & Young Data Breach Affects Personal, Financial Information

Ernst & Young Data Breach Exposes Sensitive Client Information Professional services giant Ernst & Young (EY) has been forced to notify its clients that their personal and financial information was compromised in a data breach. The incident, which occurred in late March and early April, exposed sensitive details including names, addresses, Social Security numbers, account … Read more

OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability

A recently discovered vulnerability in the OpenSSL library has left many servers vulnerable to a denial-of-service (DoS) attack that can exhaust their memory before any security handshake even takes place. The issue, dubbed “HollowByte,” affects various types of applications and servers that use OpenSSL, including Apache, NGINX, Node.js, Python, Ruby, PHP, MySQL, PostgreSQL, and others. … Read more

SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch

Critical SonicWall Zero-Days Exploited for Weeks Before Patch Release Cybersecurity firm Volexity has revealed that two recently patched vulnerabilities in SonicWall appliances were exploited by a threat actor known as UTA0533 for several weeks before patches became available. The flaws, identified as CVE-2026-15409 and CVE-2026-15410, allowed remote attackers to gain unauthorized access to SMA1000 secure … Read more