Aggregator
CVE-2026-12102 | stiofansisland UsersWP Plugin up to 1.2.63 on WordPress User Registration user_id authorization (EUVD-2026-37860)
CVE-2026-12136 | phppoet SysBasics Customize My Account for WooCommerce Plugin Shortcode wcmamtx_get_avatar_default cross site scripting (EUVD-2026-37859)
CVE-2026-12137 | phppoet SysBasics Customize My Account for WooCommerce Plugin Admin Dashboard Page plugin_options_page cross site scripting (EUVD-2026-37861)
CVE-2026-12111 | codepeople Appointment Booking Calendar Plugin up to 1.4.01 on WordPress Query Parameter cpabc_appointments_calendar_load2 ID information disclosure (EUVD-2026-37864)
CVE-2026-11395 | mariovalney CF7 to Webhook Plugin up to 5.0.0 on WordPress Placeholder server-side request forgery (EUVD-2026-37863)
CVE-2026-12098 | blubrry PowerPress Podcasting plugin by Blubrry up to 11.16.8 on WordPress update_post_meta cross site scripting (EUVD-2026-37862)
JetBrains Malicious Plugins Steal Developer API Keys
Development acceleration tools increasingly gain access to our most precious professional secrets. Malicious plugin creators for the JetBrains Marketplace deliberately exploited this profound zone of trust. Recently, a comprehensive report detailed how multiple JetBrains...
The post JetBrains Malicious Plugins Steal Developer API Keys appeared first on Information Security News.
Google Vertex AI Vulnerability Exposed in Python SDK
Cloud machine learning platforms often conceal complex infrastructures behind a few lines of code. Unfortunately, this convenient automation created a dangerous vulnerability within the Google Vertex AI SDK for Python. Specialists from Palo Alto...
The post Google Vertex AI Vulnerability Exposed in Python SDK appeared first on Information Security News.
Hostile States Behind 75% of Cyber-Attacks on UK Critical Infrastructure, NCSC Warns
Исправления нет, эксплойт есть. Microsoft оставила пользователей Windows наедине с 0Day в Защитнике
国家安全部点名预警!软件供应链投毒治理指南来了
GentleKiller targets more than 400 security processes across 48 products
Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR) products, then provide these tools directly to the affiliates who rent the gang’s encryptors. An internal data leak from the group in May 2026 confirmed the arrangement and exposed the gang’s leader discussing the supply of … More →
The post GentleKiller targets more than 400 security processes across 48 products appeared first on Help Net Security.