CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, mwEmbed (also distributed as html5lib), that allow remote, unauthenticated attackers…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
Cybersecurity researchers have uncovered an ongoing campaign distributing the Weedhack malware to gamers through fake Minecraft clients and SEO poisoning. McAfee Labs…
AI SecurityAnimateClipperCheck PointCVE-2026-58231
Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP files…
CVE-2026-32475CVE-2026-65640ElementorElementor Pro
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
PortSwigger's AI-assisted research system, HTTP Terminator, has generated and proven new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The system,…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…