News Updated 4 days ago
WordPress plugins shipped malware via official updates: CVE-2026-11976
DevelopmentSecurity
MonsterInsights Pro shipped malware after its update bucket was hijacked. The version it rolled back to was poisoned too. Three CVEs, 9.8+. Paid versions only.
2026.08.0720 views
News Updated 4 days ago
Twelve Flaws in Apache CXF: Seven Skip Checks the Spec Made Mandatory
SecurityDevelopment
Apache CXF, the Java layer enterprises use for data exchange, has six new flaws. One lets a single message take over the server. Upgrade to 4.2.3/4.1.8/3.6.12.
2026.08.0617 views
News Updated 5 days ago
Ten Flaws in Cisco IOS XE, Found by Cisco Itself — No Workarounds
SecurityInfrastructure
Cisco disclosed ten IOS XE vulnerabilities at once, the worst rated 9.8, none with a workaround. They did not surface through attacks — Cisco found them in its own internal review.
2026.08.0613 views
News Updated 5 days ago
CISA Gives Three Days to Patch TeamCity Flaw CVE-2026-63077
SecurityDevelopment
CISA gave US agencies three days to patch a TeamCity flaw that lets anyone take over the build server with no login. Self-hosted only; fixed since July 27.
2026.08.0617 views
News Updated 5 days ago
ANA Group's overseas shopping service has been down 12 days, with no word on what leaked
Japanese CompaniesSecurity
OCS FAMILY LINK SERVICE, the ANA Group's online shop for Japanese residents overseas, has been offline since 23 July after a cyberattack. As of 5 August the site does not respond, and neither the affected data fields nor the number of people involved has been published. Customers who depended on it for Japanese food and household goods have been without it for twelve days.
2026.08.054 views
News Updated 5 days ago
24 WordPress plugin flaws: two-factor authentication itself can be bypassed (CVE-2026-15372)
DevelopmentSecurity
Twenty-four WordPress plugin vulnerabilities were published on August 5, 2026, and four of them break two-factor authentication. WP 2FA never validated the second factor; miniOrange 2FA let an attacker re-point it. Four more expose password-protected content and three hand over the whole site. All 24 have fixed releases.
2026.08.0510 views
News Updated 5 days ago
10 WordPress plugin flaws, 200,000-site PrettyLinks included — all already patched (CVE-2026-9273)
SecurityDevelopment
Ten WordPress plugin vulnerabilities were published on August 5, 2026. The heaviest, in Kadence Memberships, lets an unauthenticated attacker hijack an administrator's password reset. All ten already have released fixes, the oldest from May 20 — only sites that stopped updating are at risk. PrettyLinks on 200,000 sites is included.
2026.08.054 views
News Updated 6 days ago
Five WordPress Plugin Flaws, All Ending in Account Takeover (CVE-2026-9273)
DevelopmentSecurity
Five WordPress plugin vulnerabilities were published on August 5, 2026, and all five end in account takeover. Kadence Memberships lets an unauthenticated attacker hijack an administrator's password reset; Dokan lets anyone who can register as a vendor seize an administrator account. All five already have fixed releases, so updating ends it.
2026.08.055 views
News Updated 6 days ago
Qualcomm patches 11 Snapdragon flaws: CVE-2026-25289 needs no login and no tap
MobileSecurity
Qualcomm published 11 vulnerabilities in Snapdragon and related chips on August 4. The heaviest sits in the Wi-Fi feature that discovers nearby devices, and works from within radio range with no login and no action by the user. No exploitation has been reported. Affected lists split by generation, and rollout timing is set by each handset maker.
2026.08.057 views
News Updated 6 days ago
Two Flaws in Japan's NetKids iMark Network Monitor, and No Fixed Version Exists
Japanese CompaniesSecurityInfrastructure
Two vulnerabilities were disclosed in NetKids iMark, a Japanese-made network monitoring tool, on August 5, 2026. Anyone who can log in to the machine can seize SYSTEM privileges. Every build up to and including the current V5.2.5.0 is affected and no fix has shipped. Neither works over the internet, but a monitoring server holds the map of your network. Here are the two workarounds.
2026.08.058 views
News Updated 6 days ago
Jetty auth bypass CVE-2026-10050: non-ASCII passwords collapse to ?
SecurityDevelopment
A Jetty flaw lets a login through without checking the password when it contains non-Latin characters. Only with Digest auth. Fixes for Jetty 9-11 are not free.
2026.08.0412 views
News Updated 7 days ago
LINE for Android: viewing a profile could run code (CVE-2026-16881)
SecurityJapanese CompaniesMobile
A crafted LINE profile could run code with the app's privileges on Android. The vendor rates it 8.7. The fix shipped in 26.7.2 in early summer; how to check yours.
2026.08.0414 views