Aggregator
CVE-2026-57373 | Wisetr Funnel Kit Funnel Builder PRO Plugin up to 3.15.0.4 on WordPress cross site scripting
CVE-2026-57370 | CODEPRESS IT Solutions Visitor Traffic Real Time Statistics Pro Plugin up to 11.9.1 on WordPress cross site scripting
Major Australian energy supplier confirms customer data compromised
CVE-2026-50527 | Microsoft Framework up to 4.8.1 stack-based overflow (Nessus ID 327183)
CVE-2026-50648 | Microsoft Framework allocation of resources (Nessus ID 327171)
CVE-2026-50525 | Microsoft .NET 8.0/9.0/10.0 Throttling allocation of resources (Nessus ID 327185)
CVE-2026-57425 | wpdesk Autopay dla WooCommerce Plugin up to 2.2.27 on WordPress access control
What is it Wednesdays: Episode 003.1
How attackers hosted a fake Claude download page on the claude.ai domain
A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app and clicking a sponsored Bing ad. The ad pointed to the genuine claude.ai domain, but landed on an attacker-published public artifact, which redirected them to a spoofed download site serving SectopRAT. What are Claude Artifacts? Artifacts are a … More →
The post How attackers hosted a fake Claude download page on the claude.ai domain appeared first on Help Net Security.
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
CVE-2026-57367 | Booking System Plugin up to 3.2.2 on WordPress access control
CVE-2026-65906 | JetBrains TeamCity prior 2026.1.2/2025.11.6 Kotlin DSL sandbox code injection
CVE-2026-65907 | JetBrains TeamCity prior 2026.1.2/2025.11.6 Git VCS Roots code injection
CVE-2026-65897 | Getgrav Grav Plugin up to 1.0.9 Invitations Controller create groups permission
CVE-2026-65896 | getgrav up to 1.0.9 Slug Validation PagesController::move slug path traversal
New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes
Moonshot AI’s newly unveiled Kimi K3 model is attracting considerable attention in the cybersecurity community after successfully demonstrating its ability to autonomously identify critical vulnerabilities in Redis within minutes. This 2.8-trillion-parameter AI agent reportedly discovered multiple remote code execution (RCE) vulnerabilities across various Redis versions, specifically 6.2.22, 7.4.9, 8.6.4, and 8.8.0. This highlights the increasing […]
The post New Kimi K3 AI Agent Uncovers Redis Remote Code Execution Flaws in Just 27 Minutes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.