Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites. The post Hackers Already Exploiting Newly Patched WordPress Flaws,... Read more »

AI Can Find Bugs, But Human Knowledge Still Proves Them

Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools... Read more »

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8),... Read more »

Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug

Zimbra patched nine flaws in version 10.1.20, including a critical SNMP monitoring command injection issue enabling arbitrary command execution. Zimbra released version 10.1.20 to fix nine security vulnerabilities, including... Read more »

Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access

Qilin ransomware exploits the PAN-OS GlobalProtect flaw CVE-2026-0257 to gain unauthorized VPN access to unpatched networks. Arctic Wolf researchers warn that the Qilin ransomware gang is exploiting the critical... Read more »

Jisc recommits to academic cyber collaboration network

Academic IT and network services network Jisc resigns a collaborative MoU with partners from Australia, Canada, New Zealand and the US. Read more »

Craneware Confirms Data Theft After Cyberattack, Investigations Underway

Healthcare software vendor Craneware confirmed attackers stole data during a cyberattack, underscoring growing cybersecurity risks facing healthcare suppliers. The post Craneware Confirms Data Theft After Cyberattack, Investigations Underway appeared... Read more »

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that... Read more »

OpenAI’s GPT-Red Automates Prompt Injection Testing to Harden GPT-5.6 Sol

OpenAI has disclosed details of GPT-Red, an internal automated red-teaming model that scales prompt injection vulnerability discovery with an aim to fix issues before the tools are deployed widely.... Read more »

Scottish Water taps BT, Accenture to plot digital future

Scottish utility firm inks strategic relationships with tech firms to continue digital journey, looking to deliver more resilient, secure and efficient services as well as strengthen technology foundations Read more »
Subscribe to our Newsletter