Code Defender
Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities
Publicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass.
The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on SecurityWeek.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
153 Million Driver License Images Offered on Dark Web
Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net.
The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek.
AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.
The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek.
‘Breeze Comet’ Tears Into Brazilian & Global Financial Systems
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
“FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone
“Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group’s Pegasus spyware,” the Citizen Lab said. “We found high-confidence indicators of
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
“The technique’s appeal is that node.exe (the
Recent Comments