Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Amatera Password Stealer Abuses Service Workers and Smart Contracts Do Son
    A new Amatera password stealer campaign abuses WordPress and EtherHiding. Learn how this Amatera password stealer infects browsers. Related Posts: Malicious Browser Extensions Drain Crypto Wallets PackClient RAT: New C2 Framework Sold on Telegram Miraak Post Exploitation Framework Adopts Database C2 The post Amatera Password Stealer Abuses Service Workers and Smart Contracts appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-19598: Pods Plugin Flaw Enables Complete Site Takeover, Attacks Seen in the Wild Do Son
    CVE-2026-19598 (CVSS 9.8) in the Pods WordPress plugin enables complete site takeover. Wordfence is blocking attacks in the wild. Update now. Related Posts: EverShop CVE-2026-72843 Flaw Allows Unauthenticated Account Takeover CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws Patched The post CVE-2026-19598: Pods Plugin Flaw Enables Complete Site Takeover, Attacks Seen in the Wild appe
     
  • ✇Cybersecurity News
  • CVE-2026-32475 (CVSS 9.8): Elementor Pro Flaw Risks Complete Site Compromise for 6 Million Sites Do Son
    CVE-2026-32475 (CVSS 9.8) is an Elementor Pro arbitrary file upload flaw risking complete site compromise across 6 million WordPress sites. Update to 4.2.2. Related Posts: CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws Patched CVE-2026-75501: Public PoC for Calix Router Flaw That Bypasses NAT and Firewall Protections The post CVE-2026-32475 (CVSS 9.8): Elementor Pro Flaw Risks Comp
     
  • ✇Cybersecurity News
  • CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites Do Son
    CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update to 2.10.5. Related Posts: CVE-2026-13737: Commvault Command Execution Flaws Expose Networks CVE-2026-21580: Stored XSS Hits Atlassian Confluence BeyondTrust EPM Flaws Allow Windows Privilege Escalation The post CVE-2026-18051 (CVSS 10): Unauthenticated Arbitrary File Write Hits 900k W3 Total Cache Sites appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution Do Son
    WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed GitLab Patch Release Fixes 13 Flaws, Including High-Severity XSS Bugs The post CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution Do Son
    WordPress 7.0.3 fixes CVE-2026-64638, a pre-auth XSS on the login screen that can escalate to remote code execution. CVSS 8.9. Update now. Related Posts: Metabase SQL Injection Zero-Day (CVSS 10) Exploited Multiple ClamAV Flaws Let Remote Attackers Cause DoS CryptoJS Randomness Vulnerability Drains Crypto Wallets The post CVE-2026-64638: WordPress Pre-Auth XSS Flaw Can Escalate to Remote Code Execution appeared first on Daily CyberSecurity.
     
❌
❌