News
ANA Group's overseas shopping service has been down 12 days, with no word on what leaked
Japanese CompaniesSecurity
OCS FAMILY LINK SERVICE, the ANA Group's online shop for Japanese residents overseas, has been offline since 23 July after a cyberattack. As of 5 August the site does not respond, and neither the affected data fields nor the number of people involved has been published. Customers who depended on it for Japanese food and household goods have been without it for twelve days.
2026.08.0544 views
News
24 WordPress plugin flaws: two-factor authentication itself can be bypassed (CVE-2026-15372)
SecurityDevelopment
Twenty-four WordPress plugin vulnerabilities were published on August 5, 2026, and four of them break two-factor authentication. WP 2FA never validated the second factor; miniOrange 2FA let an attacker re-point it. Four more expose password-protected content and three hand over the whole site. All 24 have fixed releases.
2026.08.0525 views
News
10 WordPress plugin flaws, 200,000-site PrettyLinks included — all already patched (CVE-2026-9273)
DevelopmentSecurity
Ten WordPress plugin vulnerabilities were published on August 5, 2026. The heaviest, in Kadence Memberships, lets an unauthenticated attacker hijack an administrator's password reset. All ten already have released fixes, the oldest from May 20 — only sites that stopped updating are at risk. PrettyLinks on 200,000 sites is included.
2026.08.0528 views
News
Five WordPress Plugin Flaws, All Ending in Account Takeover (CVE-2026-9273)
DevelopmentSecurity
Five WordPress plugin vulnerabilities were published on August 5, 2026, and all five end in account takeover. Kadence Memberships lets an unauthenticated attacker hijack an administrator's password reset; Dokan lets anyone who can register as a vendor seize an administrator account. All five already have fixed releases, so updating ends it.
2026.08.0521 views
News
Qualcomm patches 11 Snapdragon flaws: CVE-2026-25289 needs no login and no tap
SecurityMobile
Qualcomm published 11 vulnerabilities in Snapdragon and related chips on August 4. The heaviest sits in the Wi-Fi feature that discovers nearby devices, and works from within radio range with no login and no action by the user. No exploitation has been reported. Affected lists split by generation, and rollout timing is set by each handset maker.
2026.08.0532 views
News
Two Flaws in Japan's NetKids iMark Network Monitor, and No Fixed Version Exists
InfrastructureJapanese CompaniesSecurity
Two vulnerabilities were disclosed in NetKids iMark, a Japanese-made network monitoring tool, on August 5, 2026. Anyone who can log in to the machine can seize SYSTEM privileges. Every build up to and including the current V5.2.5.0 is affected and no fix has shipped. Neither works over the internet, but a monitoring server holds the map of your network. Here are the two workarounds.
2026.08.0532 views
News
Jetty auth bypass CVE-2026-10050: non-ASCII passwords collapse to ?
SecurityDevelopment
A Jetty flaw lets a login through without checking the password when it contains non-Latin characters. Only with Digest auth. Fixes for Jetty 9-11 are not free.
2026.08.0460 views
News
LINE for Android: viewing a profile could run code (CVE-2026-16881)
Japanese CompaniesMobileSecurity
A crafted LINE profile could run code with the app's privileges on Android. The vendor rates it 8.7. The fix shipped in 26.7.2 in early summer; how to check yours.
2026.08.0432 views
News
12 flaws in baserCMS, only one is traceable (CVE-2026-65875)
DevelopmentSecurity
baserCMS disclosed 12 flaws on July 30, 2026, three rated Critical. Eleven cannot be looked up by number, and Dependabot warns about none of them.
2026.08.0328 views
News
8 flaws in the chip inside four phones sold in Japan (CVE-2026-21548)
SecurityMobile
UNISOC disclosed eight chip flaws on August 1, 2026. The T8100 ships in four phones sold in Japan. All eight only cut connectivity, but no patch date exists.
2026.08.0344 views
News
27 WordPress plugin flaws, no-login admin takeover (CVE-2026-15930)
DevelopmentSecurity
27 WordPress plugin flaws landed August 3, 2026. Simple Membership (40,000+ sites) gives up the admin account with no login. Eleven need no login, 7 unfixed.
2026.08.0326 views
News
27 WordPress plugin flaws: CVE-2026-15383 hits a Japan-made plugin
DevelopmentJapanese CompaniesSecurity
27 WordPress plugin flaws went public Aug 3, 2026. One hits a Japan-made plugin on 9,000 sites: any visitor can plant script that runs in the admin dashboard. It was quietly fixed July 31.
2026.08.0328 views