πŸ” Search
Sign in to post
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCEhttps://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

Show HN: I was getting tired of looking for my travel info so I built thishttps://skaoot.com

If you've ever used TripIt or Flighty, it's similar, but focused on nomads like me, and hopefully smarter and better designed. What do you think? Comments URL: https://news.ycombinator.com/item?id=49490881 Points: 1 # Comments: 0

β†—
Berlin Refuses to Pay Hackers Who Stole Data From the City's State Networkhttps://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerablehttps://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html

Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score. Affected versions are =

Hundreds of OpenAI Agents Invaded Hugging Face Servershttps://www.darkreading.com/cyberattacks-data-breaches/hundreds-openai-agents-invaded-hugging-face-servers

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.

β†—
Offensive Security Investments Surge as AI Threats Increasehttps://www.darkreading.com/cybersecurity-operations/offensive-security-investments-surge-ai-threats-increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential β€” and risks β€” of using agentic AI for penetration testing, red teaming, and other practices.

β†—
Attackers Chain Two PaperCut Flaws to Execute Code Without Authenticationhttps://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providershttps://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting. "This new privacy standard works in tandem

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Bodyhttps://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...