Attackers Exploit miniOrange SAML Flaws to Gain WordPress Admin Access
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
CVE-2026-15981 is a critical authentication bypass vulnerability in the miniOrange SAML 2.0 Single Sign On plugin. It allows unauthenticated attackers to log…
Cisco has released security updates addressing nine vulnerabilities in its Crosswork platforms and Secure Workload software, with five of the flaws carrying…
Citrix has released security updates to address two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including a critical authentication bypass flaw that…
Cybersecurity researchers at Hunt.io have disclosed a campaign, dubbed Operation CameraSwarm, that compromised more than 14,530 Dahua devices between June 17 and…
A critical vulnerability has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Tracked as CVE-2026-15748 and…
User Profile Builder is a WordPress plugin with over 40,000 active installations, used for managing user registration and profiles. A critical authentication…
A critical authentication bypass vulnerability in Apple macOS Screen Sharing, tracked as CVE-2026-65400 (CVSS 9.8), is being actively exploited in the wild…
Threat actors have begun exploiting a newly disclosed Microsoft SharePoint vulnerability, CVE-2026-55040 (CVSS 9.1), following the public release of a proof-of-concept (PoC)…
Security researchers at Rapid7 have disclosed an AI-assisted exploit chain targeting Microsoft SharePoint Server that allows unauthenticated attackers to achieve remote code…