Security News

Over 100,000 WordPress Sites at Risk from Critical CVSS 10.0 Vulnerability in Wishlist Plugin
2025-05-29 05:34

Cybersecurity researchers have disclosed a critical unpatched security flaw impacting TI WooCommerce Wishlist plugin for WordPress that could be exploited by unauthenticated attackers to upload...

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts
2025-05-23 04:34

Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant Duo that could have allowed attackers to steal source code and inject...

Unpatched Windows Server vulnerability allows full domain compromise
2025-05-22 15:34

A privilege escalation vulnerability in Windows Server 2025 can be used by attackers to compromise any user in Active Directory (AD), including Domain Admins. “The [“BadSuccessor”] attack exploits...

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise
2025-05-22 12:35

A privilege escalation flaw has been demonstrated in Windows Server 2025 that makes it possible for attackers to compromise any user in Active Directory (AD). "The attack exploits the delegated...

ThreatLocker Patch Management: A Security-First Approach to Closing Vulnerability Windows
2025-05-21 14:02

Patching is basic cyber hygiene — but executing it at scale, securely, and fast? That's the real challenge. ThreatLocker's Patch Management flips the script with control, visibility, and Zero...

Week in review: Microsoft patches 5 actively exploited 0-days, recently fixed Chrome vulnerability exploited
2025-05-18 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patch Tuesday: Microsoft fixes 5 actively exploited zero-days On May 2025 Patch Tuesday, Microsoft...

CISA: Recently fixed Chrome vulnerability exploited in the wild (CVE-2025-4664)
2025-05-16 10:44

A high-severity Chrome vulnerability (CVE-2025-4664) that Google has fixed on Wednesday is being leveraged by attackers, CISA has confirmed by adding the flaw to its Known Exploited...

Samsung patches MagicINFO 9 Server vulnerability exploited by attackers
2025-05-15 11:15

Companies running Samsung MagicINFO, a platform for managing content on Samsung commercial digital displays, should upgrade to the latest available version of its v9 branch to fix a vulnerability...

New Chrome Vulnerability Enables Cross-Origin Data Leak via Loader Referrer Policy
2025-05-15 10:43

Google on Wednesday released updates to address four security issues in its Chrome web browser, including one for which it said there exists an exploit in the wild. The high-severity...

European Vulnerability Database goes live, but who benefits?
2025-05-14 04:15

The European Union Agency for Cybersecurity (ENISA) has unveiled the European Vulnerability Database (EUVD), an initiative under the NIS2 Directive aimed at enhancing digital security across the...