Roundup
One VPN, and a Company's Financial Close Stopped: How a Cyberattack Halts Securities Filings, and How to Defend
InfrastructureSecurity
The March 2026 cyberattack on Omikenshi ran from a VPN intrusion to a ransomware core-system halt and a delayed securities report. Using the case as an entry point, we explain how to prevent VPN intrusion and why a cyberattack stops the financial close and securities filing — from both KEV exposure data and Japan's Financial Instruments and Exchange Act, with a hands-on checklist (MFA, patching, segmentation, Zero Trust).
2026.07.1436 views
News
28 Takeover Flaws Hit WordPress Add-ons at Once, Two of Them a Perfect 10.0 — Full Plugin List and Fixes (July 13, 2026)
SecurityDevelopment
On the night of July 13, 2026, 28 dangerous flaws were disclosed at once in WordPress add-ons (plugins and themes). Sixteen are rated 9.0 or higher, two of them a worst-case 10.0, and many allow site takeover or member-data theft with no login. Affected products include the booking plugins Amelia and LatePoint and the widely bundled Kirki. Check the list for what you use and see what to do now.
2026.07.1358 views
News
July 13, 2026 Security Vulnerability Roundup: Takeovers in a Wireless Router and Industrial Gear — Does It Affect You?
SecurityInfrastructure
A roundup of three July 13, 2026 vulnerabilities rated 9.0 or higher. The Comfast wireless router can be taken over with no login yet has no fix, the WAGO industrial device has a hidden feature, and the Centreon monitoring tool has a critical flaw. Most target product operators. Also covers the same-day LINE bug so you can check what affects you.
2026.07.1339 views
News
July 12, 2026 Security Vulnerability Roundup: AI-Dev Tools Flowise and Crawl4AI Allow No-Login Takeover — Does It Affect You?
SecurityAI
A roundup of the July 12, 2026 vulnerabilities rated 9.0 or higher. The AI-app builder Flowise and the AI data-collection tool Crawl4AI both have flaws allowing no-login takeover or file overwrite, and fixes are already out. We also organize seven network-device flaws so you can check whether a product you use is affected.
2026.07.1346 views
News
LINE freezing your iPhone? Below 26.3.0 it is a known bug
SecurityMobileJapanese Companies
LINE for iPhone flaw (CVE-2026-3861): a crafted link fills the screen with pop-ups and briefly freezes the device. No data stolen. Update to 26.3.0 to fix.
2026.07.1336 views
News
PraisonAI gets four more CVEs, one at 10.0, all fixes shipped
AISecurityDevelopment
PraisonAI, a popular tool for delegating work to AI, has five flaws including the max-severity (10.0) CVE-2026-61447. A single crafted AI instruction can run malicious code on the server and steal secrets like API keys. Past PraisonAI flaws were attacked within hours of disclosure. Update both packages now.
2026.07.1142 views
News
July 11, 2026 Security Vulnerability Roundup: Seven WordPress Plugins Enable Admin Takeover — Does It Affect You?
SecurityDevelopment
A one-day roundup of the July 11, 2026 vulnerabilities we did not cover individually. Seven WordPress plugins let a single member or contributor account take over the admin, and a 2M-site Elementor add-on is among them. Judge relevance by whether a login is required, and see what ordinary users must act on now.
2026.07.1154 views
News
miniOrange login plugins need 7.8.1 — and the numbering differs
SecurityDevelopment
Two miniOrange WordPress login plugins, Social Login and Register and OAuth SSO, have critical authentication-bypass flaws (CVE-2026-12761, CVE-2026-57807, severity 9.8) that let an unauthenticated attacker take over the administrator account. Update to the latest versions now.
2026.07.1143 views
News
Exploit code published for mcp-server-kubernetes CVE-2026-61459 — and scanners stay silent
InfrastructureSecurityAI
mcp-server-kubernetes, a popular tool that lets AI assistants operate Kubernetes, has a critical flaw (CVE-2026-61459, severity 9.8): unauthenticated argument injection redirects kubectl and steals the cluster admin's credentials. Versions before 3.9.0 are affected. Update now.
2026.07.1127 views
News
Four Joomla extension flaws: Balbooa Forms 2.4.1 is not enough (CVE-2026-65880)
SecurityDevelopment
A new critical flaw in Balbooa Forms (CVE-2026-65880, CVSS 10.0) is not fixed by 2.4.1 or 2.4.2. If any form uses a Signature field, only 2.4.3 is safe. Four Joomla extension CVEs covered.
2026.07.1149 views
News
9Router default password 123456 (CVE-2026-63732): server takeover risk
DevelopmentSecurityAI
9Router, a popular AI coding router, has critical flaws (CVE-2026-55500, 9.9) that leak all stored API keys and tokens, plus a 10.0 unauthenticated RCE. Update to v0.4.80+ and don't expose it to the internet.
2026.07.11201 views
News
IntelliJ IDEA: 10.0 Remote Development hijack flaws (CVE-2026-64812) — update to 2026.2
SecurityDevelopment
IntelliJ IDEA has a critical flaw (CVE-2026-59792, severity 9.6): opening a crafted project runs attacker code on your machine. All versions before 2026.1.4 and 2026.2 are affected. Update now.
2026.07.1191 views