WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security
Google Fined 403 Million for GDPR Violations Over Users Location Data
Ireland’s Data Protection Commission (DPC) has fined Google Ireland Limited €403 million after concluding that the technology giant violated the
Microsoft: September updates break File History backup feature
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the
Claude Opus 5 Helps Researchers Weaponize HEIF Image Flaw Into Remote Code Execution
A specially crafted image file was enough to turn a normal upload feature into a potential path to server takeover.
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has appeared
Weekly Cybersecurity Newsletter Bulletin Cisco and Android 0-Day, BragJack Attack, Claude Opus 5 Used to Hack OpenAI, and 20+ Stories
This week’s roundup covers a maximum-severity Cisco ISE zero-day under active exploitation, an actively exploited Android modem flaw on Pixel
Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious
Researchers escape OpenAI Codex sandbox to run commands on host
Security researchers found two ways out of the OpenAI Codex sandbox, one of them capable of running commands on a
Business Survival in the Age ofAI
Adam Ochayon, VP of Strategy, Oasis Security Deploying agentic AI in the enterprise is no longer optional – it’s fundamental to survival. And
Autonomous AI Attacks: The Hugging Face Reality Check
For several years the forecast has been constant: AI lowers the skill barrier, AI writes novel malware, AI will soon run attacks end to
CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that attackers are actively exploiting three Linux kernel vulnerabilities, creating