WordPress backup plugin flaw exposes millions of sites to takeover attacks

A Critical Vulnerability in a Popular WordPress Backup Plugin Exposes Millions of Sites to Takeover Attacks A devastating security flaw has been discovered in the All-in-One WP Migration and Backup plugin, used by over 5 million WordPress websites. The vulnerability, tracked as CVE-2026-19949, allows unauthenticated attackers to execute remote code and take control of affected … Read more

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

A major blow has been dealt to the notorious Sality malware family, as authorities have successfully turned its own peer-to-peer (P2P) network against it. By exploiting a critical vulnerability in the malware’s communication protocol, security experts have managed to sever the flow of new malware payloads, effectively crippling the spread of this highly destructive threat. … Read more

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Malicious Software Installers Spread, Disabling Windows Update and Weakening Microsoft Defender A growing number of malicious software installers have been discovered to not only install malware on victims’ computers but also disable Windows Update and compromise Microsoft Defender’s effectiveness. These fake installers, designed to look like legitimate software packages, are being distributed via compromised websites, … Read more

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google, Anthropic, and OpenAI have just unveiled a trio of artificial intelligence models designed to safeguard against cyber threats, while also introducing new access programs aimed at promoting responsible AI development. However, these cutting-edge innovations come with a warning sign: researchers have discovered that even the most advanced AI systems can be exploited through identity … Read more

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

Cybersecurity experts are sounding the alarm about a critical vulnerability in JFrog Artifactory, a popular software repository manager used by thousands of organizations worldwide. Hackers have already begun exploiting this flaw to forge administrative access tokens, potentially allowing them to compromise downstream systems and execute malicious code. The vulnerability, identified as CVE-2026-82329, affects self-managed instances … Read more

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

A Recent Campaign Highlights the Ease of Infecting Android Devices with Malware, Exposing Users to Full Device Control A sophisticated ad campaign on Meta’s platforms has inadvertently pushed a malware-laden advertisement to users’ devices, infecting them with the notorious StreamRat Android Trojan. This particular malware strain allows attackers to gain near-complete control over infected devices, … Read more

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

A Covert BGP Hijack Exposes Thousands to Persistent Root Access In a shocking case of cyber espionage, thousands of organizations have been secretly compromised through a complex hijacking attack that leverages the Border Gateway Protocol (BGP) to inject malicious code into unsuspecting networks. The hack, attributed to an advanced threat actor, has enabled persistent root … Read more

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Brazilian Government Website Hijacked by Malicious Apache Modules, Redirects Visitors to Betting Sites A sophisticated cyber attack has compromised a Brazilian government website, redirecting thousands of visitors daily to unauthorized betting pages. The hack leverages malicious Apache modules, which are software components used to extend the functionality of the popular open-source web server. This brazen … Read more

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

A Critical Vulnerability in AI-Powered Agents Exposes Millions of Users to Malicious Code Injection A shocking discovery has been made regarding a critical vulnerability in popular artificial intelligence (AI) agents, including Claude, Codex, and Cursor. Researchers have found that malicious configuration files (.git configs) can be used to inject attacker code into these agents, putting … Read more

How to Secure Enterprise AI: From Adoption to Incident Readiness

A series of high-profile incidents has exposed a concerning trend in enterprise security: identity exposure is becoming a common entry point for active attackers. What starts as a seemingly innocuous vulnerability can quickly snowball into a full-blown breach, highlighting the need for organizations to adopt a more proactive approach to AI-driven threat detection. The phenomenon … Read more