Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
π Search
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Accesshttps://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html
US Supreme Court sides with Trump administration on mail votinghttps://www.aljazeera.com/news/2026/8/24/us-supreme-court-sides-with-trump-administration-on-mail-voting
Mail balloting has long been aΒ favourite targetΒ of US President Donald Trump.

Trump administration seeks to formalise H-1B fee of more than $100,000https://www.aljazeera.com/economy/2026/8/24/trump-administration-seeks-to-formalise-h-1b-fee-of-more-than-100000
New proposal would charge $103,265 for the US's H-1B visas, and make permanent a temporary rule challenged by courts.

