Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]
Threat actors are exploiting an unauthenticated information disclosure vulnerability in the WordPress plugin Gravity SMTP, active on 100,000 sites. [...]
Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected dev…
The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-termi…
A Copa do Mundo de 2026 acendeu um alerta no setor de cibersegurança devido ao aumento nas tentativas de golpes virtuais direcionados a consumidores e empresas. As fraudes envolvem páginas falsas de venda de ingressos, mensagens maliciosas em redes sociais e aplicativos clonados …
Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same ma…
Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of acces…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday urged Fortinet customers with FortiGate appliances to take steps to secure against ongoing malicious activity aimed at thousands of internet-accessible devices. The sweeping campaign, believed to be the…
New York, USA, 19th June 2026, CyberNewswire
Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate resp…
Pesquisadores mostraram que funções de inteligência artificial adicionadas ao Microsoft SQL Server 2025 podem ser usadas de forma indevida por invasores para acessar e retirar informações sensíveis de empresas. O problema não envolve necessariamente uma falha de segurança tradici…
Uma nova vulnerabilidade no BootROM de iPhones expõe chips da Apple a um comprometimento profundo da cadeia de inicialização segura. A falha, chamada usbliter8, afeta dispositivos com processadores A12, A13 e S4/S5. O problema foi descrito por pesquisadores da Paradigm Shift e en…
CISA has urged U.S. federal agencies to secure their systems by Sunday against a critical Splunk Enterprise vulnerability that is being exploited in attacks. [...]
Cybersecurity experts warn that active hacking networks are using fake hotel bookings, cloned websites, and live chat features to scam FIFA World Cup 2026 fans.
Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app un…
A New York man faces cyberstalking charges after allegedly sharing AI-generated nude images and fabricated racist messages using fake social media profiles to harass a Georgia college student. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed "FortiBleed." [...]
Crypto Clipper spreads over USB and communicates over Tor.
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. [...]
Invasores estão explorando massivamente uma vulnerabilidade no complemento Gravity SMTP desenvolvido para a plataforma WordPress. De acordo com os relatórios de telemetria emitidos pela empresa de cibersegurança Wordfence, a falha estrutural permite que agentes maliciosos não aut…
Pelo menos 50 empresas de grande porte no Brasil, incluindo organizações com mais de 10 mil funcionários e atuação nos setores financeiro, industrial, de telecomunicações e varejo, estão entre as vítimas da campanha FortiBleed que comprometeu 73.932 firewalls Fortinet globalmente…