CVE-2026-32475: Elementor Pro File Upload RCE
Critical vulnerability in Elementor Pro WordPress plugin allowing unauthenticated attackers to upload PHP files and execute code. CVSS 9.0. Affects versions up to 4.2.1. Patched in 4.2.2.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
Critical vulnerability in Elementor Pro WordPress plugin allowing unauthenticated attackers to upload PHP files and execute code. CVSS 9.0. Affects versions up to 4.2.1. Patched in 4.2.2.
Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP files…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active…
CVE-2021-33044 is an authentication-bypass vulnerability in Dahua IP cameras and related products. Attackers can bypass device identity authentication by constructing malicious data…
CVE-2021-33045 is an authentication-bypass vulnerability in Dahua IP cameras. It involves a loopback login request using the 127.0.0.1 address. The flaw allows…
CVE-2024-39943 is an operating-system command-injection flaw in Rejetto HFS. It was associated with the recovered tooling in the Operation CameraSwarm campaign but…
Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker…
OpenAI has announced a temporary pause in reinforcement learning (RL) training for its most advanced AI models to strengthen safety and security…
Phishing has evolved from malicious content (Phishing 1.0) to malicious intent (Phishing 2.0) and now to AI-powered, multi-channel attacks (Phishing 3.0). In…
Cybersecurity researchers at Hunt.io have disclosed a campaign, dubbed Operation CameraSwarm, that compromised more than 14,530 Dahua devices between June 17 and…
A threat actor calling itself 'Ransom Busters' is targeting ransomware victims with a novel extortion scheme, offering to delete stolen data from…
Researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads, dubbed "mind viruses," can spread between AI agents through editable system…
A newly uncovered cyber espionage operation dubbed SilkParasite has been targeting government bodies in Central Asia, according to a technical report from…
SilkParasite is a China-nexus cyber espionage threat cluster first discovered in late 2025. It targets government bodies in Central Asia, using a…
UAC-0063 is a threat actor previously identified as targeting Central Asia, often using cyber espionage tactics. It is one of the groups…
FamousSparrow is a threat actor known for targeting government entities in Central Asia, often exploiting vulnerabilities in web applications and using custom…
A set of 40 malicious Mozilla Firefox extensions has been discovered masquerading as popular Web3 products like OKX, Rabby Wallet, and TronLink…
A campaign dubbed 'Offside Wallet Theft Factory' involves 40 malicious Firefox extensions that masquerade as Web3 products to steal cryptocurrency wallet secrets.…
DriveSilkRAT is a newly discovered remote access tool written in .NET/C++ that uses Google Drive as its command-and-control channel. It supports 12…
CookiETagRAT is a C++-based remote access tool that uses HTTP Cookie and ETag response headers as its command-and-control mechanism to receive and…
Researchers presented a survey of Ledger breach victims at USENIX Security '23, documenting spam, scams, phishing, and safety concerns following the 2020…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
The GCIH certification demonstrates proficiency in incident handling and response, often pursued after SANS SEC504 training.
The SEC660 course at SANS Network Security 2026 teaches how to leverage AI for automating tasks while maintaining deep manual understanding of…
SANS SEC504 is a training course covering hacker tools, techniques, and incident handling, leading to GCIH certification.
OKX was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
TronLink, a Web3 wallet, is among the products impersonated by malicious Firefox extensions designed to steal recovery phrases and private keys.
A popular WordPress page builder plugin. Versions up to 4.2.1 are vulnerable to unauthenticated PHP upload and RCE (CVE-2026-32475). Patched in 4.2.2.
The V8 Sandbox is a security mechanism in the V8 JavaScript engine that limits transient access to 64-bit pointers, helping to mitigate…
Rabby Wallet was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
TronLink was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Supabase was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
API-Sports was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.
Fifteen malicious Firefox extensions exfiltrate wallet secrets through Cloudflare Workers, leveraging the service for data theft.
msaRAT uses Twilio TURN relays to establish WebRTC DataChannels between the browser and C2 server.