Critical WordPress WooCommerce Plugin Flaw Allows Full Account Takeover Without Login
CVE-2025-10484 is a critical authentication bypass vulnerability affecting a WordPress plugin used for mobile-number-based registration and login…
continue reading..
Attackers Exploit Trusted Windows Utility ahost.exe in Stealthy Multi-Actor Malware Campaign
Modern malware campaigns are increasingly shifting away from noisy exploits and instead abusing trusted binaries already present…
continue reading..
Mandiant’s Bold Move: Releasing Rainbow Tables to Force Legacy Protocol Retirement
Security firm Mandiant, now part of Google Cloud, recently made a striking decision: it publicly released a…
continue reading..
Grok AI Breach on X Sparks Global Alarm Over Deepfake Abuse and Platform Safety
Grok AI — the generative AI chatbot developed by Elon Musk’s xAI and integrated with X —…
continue reading..
Irish Ombudsman Cyberattack Triggers Prolonged Service Disruption
A ransomware attack on Ireland’s Office of the Ombudsman in December 2025 has caused serious operational disruption,…
continue reading..
January 2026 Microsoft Security Update Breaks Remote Desktop Sign-In
Microsoft’s January 13, 2026 security update (most notably KB5074109 for Windows 10 and Windows 11, along with…
continue reading..
Browser-in-the-Browser Phishing Is Surging: How the Attack Works and How to Spot It
Browser-in-the-Browser (BitB) phishing attacks are gaining momentum because attackers are reviving and refining the technique to evade…
continue reading..
CVE-2024-48077: NanoMQ Broker DoS via Uncontrolled Receive Queue Exhaustion
CVE ID: CVE-2024-48077Product: NanoMQ MQTT BrokerAffected version: NanoMQ v0.22.7Vulnerability type: Denial of Service (Resource Exhaustion / Deadlock)CVSS…
continue reading..
CVE-2026-0897: Keras Model Load “Memory Bomb” – One File Can Crash Your ML Service
CVE ID: CVE-2026-0897Product: Google KerasVulnerability Type: Memory Exhaustion / Denial of Service (DoS)Severity: HighCVSS Score: 7.1 (High)Attack…
continue reading..
