Security researcher Puja Srivastava from Sucuri uncovered two malicious files designed to guarantee persistent attacker access by...
Web Security
Adobe has broken from its regular patch schedule to release an emergency fix for CVE-2025-54236, a vulnerability...
The Astro project has disclosed a high-severity vulnerability in its Cloudflare adapter, tracked as CVE-2025-58179 (CVSS 7.2)....
A newly disclosed security flaw, tracked as CVE-2025-54370, has been identified in PhpSpreadsheet, a PHP-based library that...
The well-known Certificate Authority Buypass has announced that it will cease issuing TLS/SSL digital certificates in October...
A high-severity zero-day vulnerability in Google Chrome’s V8 JavaScript engine, tracked as CVE-2025-5419, has been exposed, with...
The Directus project has disclosed a critical vulnerability tracked as CVE-2025-55746 (CVSS 9.3) that could allow unauthenticated...
A critical security vulnerability has been disclosed in sha.js, a widely used JavaScript library that implements the...
The asynchronous framework server software and reverse proxy NGINX has recently announced the release of an ACME...
In a recent investigation, Kayleigh Martin, a Security Analyst at Sucuri, uncovered a cunning new tactic used...
Cloudflare, the global internet services provider, has recently introduced an AI Crawler Leaderboard—a dynamic red-and-black list designed...
Sucuri’s Puja Srivastava recently uncovered a stealthy and complex malware campaign targeting WordPress websites that left no...
The Wordfence Threat Intelligence Team has unveiled a powerful malware framework operating under the guise of a...
Last month, a critical vulnerability was reported to Wordfence that now threatens more than 22,000 WordPress websites...
A Server-Side Request Forgery (SSRF) vulnerability has been discovered in the @opennextjs/cloudflare package, potentially allowing unauthenticated users...
A significant surge in brute-force attacks is targeting Apache Tomcat Manager interfaces, according to a new report...
The Spring project has released a security advisory disclosing a vulnerability in the popular Spring Framework, which...
Elastic has disclosed a high-severity vulnerability (CVE-2024-43706) affecting its Kibana observability platform, specifically in the Synthetic Monitoring...
Security researcher Matt Palmer has uncovered a critical vulnerability in the Lovable low-code platform, now tracked as...
A severe vulnerability in the PayU CommercePro plugin for WordPress, which has over 5,000 active installations, allows...
A newly disclosed vulnerability in the Auth0 PHP SDK—a widely-used authentication toolkit with over 16 million downloads—poses...
The ModSecurity project has issued a security advisory disclosing a new vulnerability—CVE-2025-48866—in its widely used open-source web...