WordPress – XSS Flaw

August 7, 2026 Faeem 0

Overview WordPress has patched a pre‑authentication reflected cross‑site scripting (XSS) flaw in its login screen that affects every version of the CMS. Tracked as CVE‑2026‑64638 […]

WSUS Servers to Deliver Malware

August 7, 2026 Faeem 0

Overview New research from SpecterOps reveals how adversaries can hijack Windows Server Update Services (WSUS) to deliver malware disguised as trusted updates. By exploiting architectural […]

GitHub Issue

August 7, 2026 Faeem 0

Overview Security researchers at Novee Security revealed critical flaws in Claude Code and Google’s Gemini CLI that allowed unprivileged GitHub issues to reach CI/CD workflow […]

Zbtlink Routers – Hidden Backdoor

August 7, 2026 Faeem 0

Overview Security analysts at VulnCheck have discovered a hidden remote‑control implant inside more than 20 models of Zbtlink routers sold globally. The implant, named ENDLESSDOORS, […]

GPT – Unlimited Text Chats

August 7, 2026 Faeem 0

Overview OpenAI has announced a major expansion of ChatGPT access, rolling out its updated GPT‑5.6 models to Free and Go tier users while removing text […]

macOS Attacked

August 7, 2026 Faeem 0

Overview Security researchers at Huntress have uncovered a Go‑based macOS infostealer delivered through ClickFix phishing attacks. This malware is designed to steal cryptocurrency assets, browser‑stored […]

AI Exposed

August 6, 2026 Faeem 0

Overview For years, enterprise security focused on endpoints and networks. As organizations moved to SaaS and cloud, identity and data protection controls became central. But […]

Oracle Database Exploited

August 6, 2026 Faeem 0

Overview On July 27, 2026, Huntress researchers uncovered a sophisticated attack where hackers exploited a SQL injection vulnerability to install the khunt post‑exploitation toolkit directly […]

AWS, Google, and Vercel Agent Flaws

August 6, 2026 Faeem 0

Overview Security researchers have uncovered critical flaws in agent infrastructures from AWS, Google, and Vercel that allowed attackers to trigger tool execution without any model […]