BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
Eight security flaws in NodeBB were disclosed on July 24, 2026, along with exploit code. Discovered by Aikido Security's AI pentest agents…
The Classic Web Client in Zimbra had four XSS vulnerabilities patched, including stored XSS via attachment filenames and crafted fields.
Zimbra has disclosed a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that could allow attackers to execute arbitrary…
A suspected China-aligned threat activity cluster tracked as UNK_MassTraction by Proofpoint has been exploiting critical Roundcube webmail vulnerabilities to target physics and…