pwn.ai Discovers Critical WordPress XSS Chain
pwn.ai, a security research firm, discovered and responsibly disclosed CVE-2026-64638, a pre-authentication XSS vulnerability in WordPress that can lead to PHP code…
pwn.ai, a security research firm, discovered and responsibly disclosed CVE-2026-64638, a pre-authentication XSS vulnerability in WordPress that can lead to PHP code…
Synack, a security company, confirmed that researcher Malcolm Stagg tested NatJack techniques against dozens of real-world network infrastructure products from multiple vendors…
Researchers Daniël Trujillo and Mengjia Yan from MIT CSAIL discovered the Interrupt Injection attack, which bypasses Spectre v2 defenses on Intel and…
The research paper on Interrupt Injection is scheduled to be presented at USENIX Security in Baltimore. The paper details the TONTOU attack…
Block is a security research firm that traced the Coldcard firmware flaw to a production config issue in the libngu library, which…
FearsOff Cybersecurity, through researcher Kirill Firsov, responsibly disclosed CVE-2026-16723 to Alibaba on July 21, 2026.
Beginning July 27, 2026, GitHub will reduce public bug bounty payouts by at least 50% across all severity levels, moving top rewards…
Arctic Wolf Labs, the research division of Arctic Wolf, identified and analyzed a widespread AitM phishing campaign targeting Microsoft 365 accounts. Their…
Researchers have demonstrated that open-source Android AI agent frameworks are vulnerable to a novel attack chain where invisible screen text can lead…
Landon Peng of Lunbun LLC reported the CVE-2026-14266 vulnerability to 7-Zip on June 5, 2026. Lunbun LLC is a security research firm.