Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
The vulnerabilities, according to Wordfence and Patchstack, are listed below –
CVE-2026-76581 (CVSS score: 9.8) – An authentication bypass flaw in
Brave browser adds email aliases to help users evade tracking
Hasbro Data Breach Exposed Employee Personal Information
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek.
McKesson discloses breach after ShinyHunters claims patient data theft
Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network
The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score.
Affected versions are < 0.6.2 and >=
PaperCut releases second emergency patch for exploited flaws
GiveWP WordPress donation plugin flaw lets hackers execute server commands
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
“This vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which could be used to execute arbitrary Java code inside the application’s
