The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces back to one server: 158.220.87.79, hosted on a
Microsoft tests faster Windows File Explorer, new context menu
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.
The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.
CISA: Windows Task Host flaw now exploited by ransomware gangs
Microsoft confirms outage affecting search in Microsoft 365 apps
Heights Finance Data Breach Impacts at Least 1.2 Million Individuals
Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.
The post Heights Finance Data Breach Impacts at Least 1.2 Million Individuals appeared first on SecurityWeek.
SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers
The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line “[Important] Your SafePal Order
GitLab Patches Critical Code Injection Vulnerability
The security defect allows unauthenticated attackers to modify or delete user data and public projects.
The post GitLab Patches Critical Code Injection Vulnerability appeared first on SecurityWeek.
Microsoft starts removing WMIC tool used by cybercriminals
Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates
The bugs could be exploited to crash Safari, corrupt memory, leak sensitive data, escape the sandbox, and exfiltrate data.
The post Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates appeared first on SecurityWeek.
