Splunk AI Toolkit Flaw Lets Admins Run Arbitrary OS Commands
Splunk has disclosed a critical security vulnerability in...
CVE-2026-4020: Gravity SMTP Flaw Exposes 100K WordPress Sites
Threat actors are actively exploiting a critical security...
Critical Joomla Plugin Flaw Allows Unauthenticated PHP Code Execution
A critical improper access control vulnerability has been...
OpenBSD PAP Auth Bypass Flaw Lurked Undetected for 27 Years
A critical authentication-bypass vulnerability hiding in...
CISA Adds Oracle PeopleSoft CVE-2026-35273 to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency...
UNC3753 Targets U.S. Law Firms With Hybrid Extortion Attacks
A financially motivated threat actor tracked as UNC3753,...
ShinyHunters Breaches Infinite Campus, Leaks 137,000 User Records
The popular K-12 student information system Infinite Campus...
CVE-2026-42824: Microsoft 365 Copilot Search Leak Flaw Patched
A critical vulnerability chain in Microsoft 365 Copilot...
OptinMonster Supply Chain Attack Hits 1.2M WordPress Sites
A sophisticated supply chain attack targeting the widely...
Palo Alto GlobalProtect VPN Flaw Actively Exploited in the Wild
Palo Alto Networks Unit 42 has confirmed active...