-
A sophisticated threat campaign, referred to as “City-Forum,” is targeting publicly accessible Salesforce Experience Cloud sites and ServiceNow Service Portals, aiming to enumerate and extract data exposed to anonymous users. Security firm Reco, which …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Palo Alto Networks has released security advisories for multiple vulnerabilities in the GlobalProtect App that could allow a local attacker to elevate their privileges to SYSTEM on Windows or to root on Linux and macOS systems. These advisories were pu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WordPress has released version 7.0.4 to address a high-impact authenticated remote code execution (RCE) vulnerability. This flaw could allow users with Author-level privileges or higher to execute code on affected websites. The vulnerability, tracked a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Nightmare-Eclipse, also known as Chaotic Eclipse, has released a new Windows privilege escalation exploit named ShieldBreak. This exploit claims to bypass Microsoft’s July 2026 fix for the RoguePlanet Windows Defender vulnerability,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses observed across 47 countries. This campaign reportedly began within days of the public disclosure an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical SQL injection vulnerability in Metabase, adding it to its Known Exploited Vulnerabilities (KEV) Catalog. This flaw allows unauthenticated remote attackers to gai…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Chrome Web Store operation that turns “free VPN” extensions into browser-wide traffic relays controlled by a single proxy provider. The campaign comprises 737 extensions published by at least 40 developer accounts, with 274 masquerading as 66 recogni…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google Chrome has implemented enhanced defenses aimed at disrupting abusive web push notifications that are often used to distribute malware, phishing attempts, fraudulent payment requests, and scam content. This initiative combines browser-based permi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Corporate network access is becoming both cheaper to obtain at scale and vastly more valuable at the top end of the criminal market. That contradiction defines the identity threat economy entering 2026: billions of stolen credentials have made basic lo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Google has released Chrome version 151.0.7922.137/138 for Windows and macOS, and version 151.0.7922.137 for Linux. This update addresses five high-severity security vulnerabilities, all use-after-free (UAF), that affect various Chrome components, inclu…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


