Google is changing how some search-result links behave. Certain results now pass through an encoded Google redirect rather than opening the listed site, making a browser’s link preview less useful …
New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Phishing is arriving via trusted email systems. Instead of using obvious malicious addresses, attackers send ordinary account alerts, invoices and renewal notices that lead victims into web-based traps. The approach …
Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns …
Critical WordPress Plugin Flaws Put Over 600,000 Websites at Risk of Takeover
Two critical vulnerabilities in The Events Calendar WordPress plugin could allow unauthenticated attackers to take over vulnerable websites. The flaws affect more than 600,000 active installations. They can lead to …
Hackers Actively Exploiting Gitea n-day RCE Vulnerability in the Wild to Hijack Instances
Hackers are actively exploiting a critical Gitea remote code execution vulnerability, tracked as CVE-2026-60004, to compromise internet-facing source-code management servers. Researchers found that a Chinese-speaking threat actor, named Red Heron, …
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP With $159 DDR5 Device
Confidential cloud systems are designed to keep a customer’s data hidden even from the server operator. DDRop shows that this promise can fail when an attacker can tamper with the …
Telegram Desktop Flaw Lets Attackers Steal Chat Messages Through Poisoned HTML Exports
A high-severity Telegram Desktop vulnerability let attackers hide JavaScript in bot-created inline keyboard buttons and steal chat content when victims exported conversations as HTML files. Telegram fixed the issue in …
Hackers Use Autonomous AI Agents to Harvest Thousands of Credentials in Under 6 Hours
Cybercriminals are using autonomous AI agents to turn compromised cloud systems into rapid credential-harvesting platforms. In a newly documented case, a suspected financially motivated actor planned, built, and ran a …
Microsoft Confirms KB5002914 Update Breaks Copy and Paste on Excel
Microsoft has confirmed that the September 8, 2026 Excel security update KB5002914 can silently break copy and paste in Excel 2016, 2019, 2021, and 2024. Microsoft added the defect to …
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
Threat actors have been observed exploiting a critical remote code execution vulnerability in the Marimo notebook platform to steal AWS credentials and authenticate to an SSH bastion host within eight …
