CVE-2025-13592: One Shortcode Away from Full Server Compromise in WordPress
Executive Summary (Quick Facts) What Is CVE-2025-13592? CVE-2025-13592 is a Remote Code Execution vulnerability in the Advanced…
continue reading..
CVE-2025-68861: When “Logged-In” Is Enough — Plugin Optimizer Breaks WordPress Access Control
Executive Summary (Quick View) What Is CVE-2025-68861? CVE-2025-68861 is a missing authorization vulnerability in the WordPress plugin…
continue reading..
CVE-2024-30855: Silent Admin Takeover Risk in DedeCMS via CSRF
Executive Summary (At a Glance) Vulnerability Overview CVE-2024-30855 is a Cross-Site Request Forgery (CSRF) vulnerability affecting DedeCMS…
continue reading..
CVE-2025-68706 – One Malicious Web Request Can Crash or Compromise KuWFi Routers
CVE ID: CVE-2025-68706Vulnerability Type: Stack-based Buffer OverflowAffected Component: GoAhead-Webs HTTP daemonAffected Product: KuWFi 4G LTE AC900 RouterAffected…
continue reading..
CVE-2025-13592 vulnerability affecting the Advanced Ads WordPress plugin
CVE-2025-13592 is a high-severity remote code execution (RCE) vulnerability affecting the Advanced Ads WordPress plugin (also known…
continue reading..
Telecom Sector Under Sustained Attack — Technical View
1. APT Activity: Targeting Signaling, Core, and Management Planes Attack Surface Common Techniques Impact 2. Supply-Chain Compromise:…
continue reading..
Highly sophisticated malware campaign targeting Maven Central
Security researchers have uncovered what appears to be the first highly sophisticated malware campaign targeting Maven Central,…
continue reading..
From User-Mode to Ring-0: Mustang Panda’s Shift to Kernel-Level Espionage
Recent activity linked to Mustang Panda (also tracked as HoneyMyte or Bronze President) shows a clear shift…
continue reading..
Romanian Waters (Apele Române) Ransomware Attack
Systems Impacted The attack disrupted large parts of the organization’s IT infrastructure, including: However, operational technology (OT)…
continue reading..
