WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 A critical vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and nicknamed XSS2Shell, that turns a single failed login attempt into full remote code execution on the …

18-Year-Old Linux Kernel SCTP Vulnerability Lets Attackers Gain Full Root on Host

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 A newly disclosed Linux kernel vulnerability, dubbed SCTPhantom and tracked as CVE-2026-64564, allows attackers to escalate from unprivileged local access to full root and even escape containers …

Malware Abuses Windows Hello for Business Key to Authenticate Microsoft Entra ID

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 A newly demonstrated technique shows how malware in a compromised Windows user session can abuse Windows Hello for Business (WHFB) cryptographic keys to authenticate to Microsoft Entra …

CVE-2026-64561 Zapscape Lets KVM Guests Escape to Linux Host With Root Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 A Linux kernel vulnerability, tracked as CVE-2026-64561 and named Zapscape, could allow attackers to escape a KVM virtual machine and take control of its underlying Linux host …

Google Chrome 151 Fixes 41 Security Flaws, Including 6 Critical Memory Bugs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 Google has released Chrome 151 to the Stable channel, fixing 41 security vulnerabilities, including six critical memory-safety flaws that could enable browser crashes, memory corruption, or malicious …

Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT). The incident resulted in the compromise …

Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 An indirect prompt injection vulnerability in Claude on Chrome can be exploited to steal email verification codes and hijack accounts on platforms like Slack, X, and Claude.ai. The attack …

ChainDrop Worm Infects 400+ npm Packages to Steal GitHub and Cloud Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

August 7, 2026 ChainDrop has turned routine software installs into a route for credential theft. The self-propagating worm infected more than 400 npm packages, putting developer laptops, build systems and …