WordPress arbitrary code execution vulnerability
CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks.
1100 articles
CVE-2026-87902, a new critical vulnerability in the WordPress core, is already being actively exploited in real-world attacks.
What tokenomics is, and how the value of AI tokens has become a cybersecurity issue.
We believe that investing in cybersecurity, like any other investment, should pay off. This post explains what a small company needs to make its security setup work for the business instead of staying a formality.
We break down the file formats that can be unfamiliar to some users, and that aren’t always scanned by security solutions but can still pose cyberthreats.
Attackers are crafting files that devices can read as two different document types at once, and using these “nesting dolls” to smuggle in malware. How to detect and neutralize these two-faced files?
How attackers distribute ScreenConnect under the guise of free software to deploy AsyncRAT.
We analyze the first-ever real-world incidents where attackers targeted AI agents deployed in corporate environments.
A new variation of ClickFix allows attackers to gain access to Microsoft 365 accounts. We break down how this technique works, and what threat it poses to organizations.
How attackers gain access to corporate services without stealing passwords or cookies: we’re analyzing the Shadow Token via Remote Debug technique used in ToddyCat APT attacks.
Microsoft has addressed approximately 600 vulnerabilities in its products, affecting its entire product line — including even Minecraft Server and Age of Empires II. How can organizations handle such a volume?
A GReAT study has identified ~250,000 potential security issues in publicly accessible GitHub Actions.
Austrian researchers have uncovered a bizarre new way hackers could steal sensitive data.
How to detect and block unauthorized AI tools in an organization.
Attempts at hijacking AI resources are now taking place on an industrial scale. How is AI infrastructure being targeted, and what defensive measures should you implement?
A targeted supply chain attack via popular software for mounting disk images.
How and why droids from a galaxy far, far away switch their allegiances.
Building a functional app without programming skills is now a possibility, but maintaining it and ensuring cybersecurity remains a challenge. Here are several protective measures that even non-technical creators can implement.
Researchers have established that fiber-optic cables can be exploited for eavesdropping. We’re breaking down how feasible such an attack is in a real-world scenario.
We’re breaking down why developers have moved into the crosshairs, the specific tactics attackers are using, and how to reduce the risks of company infrastructure being compromised.
GDDRHammer, GeForge, and GPUBreach: three new research papers diving into attacks that exploit the Rowhammer technique.