According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler
Remote, unauthenticated attackers could exploit the critical-severity flaw without user interaction.
The post Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler appeared first on SecurityWeek.
Critical GitLab Flaw Exploited Shortly After Disclosure
CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.
The post Critical GitLab Flaw Exploited Shortly After Disclosure appeared first on SecurityWeek.
Hackers Using AI to Target Siemens PLCs in Critical US Sectors
A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.
The post Hackers Using AI to Target Siemens PLCs in Critical US Sectors appeared first on SecurityWeek.
Microsoft says August Windows updates may cause gaming issues
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.
“The flaw lives in the Forms module’s File
