Critical WordPress Plugin Flaw Allows Hackers to Create Admin Accounts Without Login (CVE-2025-14533)
CVE-2025-14533 is a critical unauthenticated privilege-escalation vulnerability affecting the Advanced Custom Fields: Extended (ACF Extended) WordPress plugin.…
continue reading..
Hacktivists Escalate Cyberattacks on Global Critical Infrastructure in 2025, Raising Geopolitical Security Concerns
In 2025, the global cyber threat landscape shifted dramatically as hacktivist groups evolved from nuisance actors into…
continue reading..
Operation Nomad Leopard: Spear-Phishing Campaign Targets Afghan Government Systems with Stealthy ISO-Based Malware
Security team published an analysis of an ongoing targeted spear-phishing campaign—Operation Nomad Leopard—designed to infiltrate government computers…
continue reading..
Researchers Warn LLMs Are Driving the Industrialisation of Software Exploits
The world of offensive cybersecurity is on the brink of a profound transformation. Recent experiments with advanced…
continue reading..
When Trust Becomes the Weapon: How Open-Source Python Tools Are Powering Social Media Phishing Attacks
Cybersecurity researchers have uncovered an increasingly sophisticated phishing campaign that leverages two seemingly innocuous technologies — open-source…
continue reading..
Security Flaws in Anthropic MCP Git Server Expose File Access and Enable Code Execution
The git_init tool in the server would accept an arbitrary filesystem path and turn that path into…
continue reading..
Raaga Suffers Major Data Breach, Exposing Personal Information of 10.2 Million Users
Indian music streaming platform Raaga has suffered a major data breach that exposed the personal information of…
continue reading..
Critical Flaw in TP-Link VIGI Cameras Lets Local Network Attackers Reset Admin Passwords Without Authentication
CVE-2026-0629 is a high-severity authentication bypass vulnerability affecting multiple VIGI and VIGI InSight IP camera models. The…
continue reading..
CVE-2026-1221: Hard-Coded Credentials Enable Remote Access to PrismX MX100 Infrastructure
CVE-2026-1221 describes a critical security flaw caused by hard-coded credentials embedded in the firmware of the PrismX…
continue reading..
