WordPress Pre-Auth XSS Flaw CVE-2026-64638 Could Lead to PHP Code Execution
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
PortSwigger's AI-assisted research system, HTTP Terminator, has generated and proven new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. The system,…
Burp Suite is a comprehensive web vulnerability scanner and proxy tool developed by PortSwigger. It is widely used for security testing and…
A new class of prompt injection attack, dubbed "AI Recommendation Poisoning," is spreading across commercial websites. It exploits pre-filled deep links in…
Unit 42 researchers have disclosed three attack paths against Google Password Manager in Chrome on Windows, which could allow malware already running…
Attackers compromised a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.…
Russian threat actors linked to the exploitation of a Zimbra vulnerability have been observed exploiting CVE-2026-42897, a cross-site scripting (XSS) flaw in…
Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies to siphon funds…
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit for a remote code execution (RCE) vulnerability in self-managed…
A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITYSYSTEM on Microsoft's production image-processing workers, and as root on…