Aggregator
New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited SQL injection vulnerability in WordPress Core that could allow attackers to compromise websites and potentially achieve remote code execution. This flaw, tracked as CVE-2026-63030, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026. This designation […]
The post CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild appeared first on Cyber Security News.
Glow exits stealth with $180 million to secure the AI-enabled endpoint
Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The company will use the funding to expand its go-to-market team in the United States and grow Glow Labs, its cybersecurity research division. Glow was founded … More →
The post Glow exits stealth with $180 million to secure the AI-enabled endpoint appeared first on Help Net Security.
Stop renting storage space — this lifetime 2TB plan is yours for $59
Дипломаты Южной Кореи умеют хранить государственные секреты — а вот свои пароли уберечь не смогли
【安全圈】新型 HollowGraph 恶意软件滥用 Microsoft 365 日历进行 C&C 通信
【安全圈】Chick-fil-A 在凭证填充攻击后披露数据泄露事件
【安全圈】AI首次“叛变”!OpenAI模型自主攻击友商系统
OpenKVM-A2:把向日葵控控 A2 改造成开源本地 KVM
LG 将封禁住宅代理智能电视应用
US seizes over 1,000 domains used for illegal World Cup 2026 streams
The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rounds took down nearly 400 domains by the end of June, and two later rounds pushed the total past 1,000. The effort, named “Operation Offsides”, was led by the … More →
The post US seizes over 1,000 domains used for illegal World Cup 2026 streams appeared first on Help Net Security.
Ubuntu snap-confine Vulnerability Enables Local Root Access
U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
Microsoft to stop Exchange 2016 / 2019 security updates in October
尼安德特人可能和现代人类一样聪明
Lookout identifies exploitable vulnerabilities in mobile apps
Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem. The advancement of frontier AI models, such as Anthropic’s Claude Mythos, marks a fundamental shift in the cybersecurity landscape. By reducing the cost and time required to discover vulnerabilities, develop exploits, and orchestrate sophisticated attacks, AI … More →
The post Lookout identifies exploitable vulnerabilities in mobile apps appeared first on Help Net Security.
Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws
Zimbra has released version 10.1.20 of its Collaboration Suite (ZCS) to address multiple high-severity security vulnerabilities. This release includes a critical command injection flaw in the SNMP monitoring component and several cross-site scripting (XSS) issues affecting the Classic Web Client. The update, published on July 20, 2026, provides a permanent fix for a previously disclosed […]
The post Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Multiple XSS Flaws appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.