Vulnerability

WordPress Theme RCE Vulnerability Actively Exploited to take Full Site Control

A critical security vulnerability in the popular "Alone" WordPress theme has been actively exploited by cybercriminals to gain complete control…

9 months ago

BeyondTrust Privilege Management for Windows Vulnerability Allows Attackers to Escalate Privileges

A critical security vulnerability has been discovered in BeyondTrust's Privilege Management for Windows software that enables local authenticated attackers to…

9 months ago

SonicWall SSL VPN Vulnerability Allows Attackers to Launch DoS Attacks on Firewalls

SonicWall has disclosed a significant security vulnerability affecting its Gen7 firewall products that could allow remote attackers to disrupt network…

9 months ago

Critical AI Vibe Coding Platform Vulnerability Exposes Unauthorized Access to User Private Apps

A critical security vulnerability in Base44, a popular AI-powered "vibe coding" platform recently acquired by Wix, that allowed unauthorized access…

9 months ago

Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

A sophisticated attack targeting a U.S. chemicals company, where threat actors exploited a critical SAP NetWeaver vulnerability to deploy the…

9 months ago

Critical Chrome Vulnerability Allow Attackers to Control Memory and Run Arbitrary Code

Google has released a critical security update for Chrome, addressing multiple high-severity vulnerability that could allow attackers to manipulate system…

9 months ago

Gemini CLI Vulnerability Allows Silent Execution of Malicious Commands on Developer Systems

A critical security vulnerability in Google's Gemini CLI tool allowed attackers to execute malicious commands on developers' systems without detection,…

9 months ago

Severe CodeIgniter Vulnerability Leaves Millions of Web Applications Open to File Upload Exploits

A critical security vulnerability has been discovered in CodeIgniter4's ImageMagick handler that could allow attackers to execute arbitrary commands on…

9 months ago

New macOS Vulnerability Allows Attackers to Steal Private Data by Bypassing TCC

A critical macOS vulnerability that enables attackers to steal sensitive private data normally protected by Apple's Transparency, Consent, and Control…

9 months ago

CISA Issues Warning on Exploited PaperCut RCE Vulnerability in Ongoing Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting PaperCut NG/MF print management software to its…

9 months ago