Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

20/08/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475,

OpenAI Pauses Frontier RL Training as It Tightens Defenses Against Unsafe AI Behavior

19/08/2026 0 Comments 0 tags

OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the

Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

19/08/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12

Phishing 3.0: The Fight Moves to Agent Versus Agent

19/08/2026 0 Comments 0 tags

Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload,

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

19/08/2026 0 Comments 0 tags

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

19/08/2026 0 Comments 0 tags

A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

19/08/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

19/08/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

19/08/2026 0 Comments 0 tags

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

19/08/2026 0 Comments 0 tags

Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware