WordPress has just released a security-focused update — version 7.0.4 — to close a remote code execution flaw that can be triggered when images are processed with the Imagick extension and Ghostscript. The vulnerability, tracked as CVE-2026-65640 and described in GHSA-8vr3-7mxf-gx8w, was responsibly disclosed by researchers at pwn.ai. While exploitation requires an authenticated Author-level account or higher, the bug’s mechanics
Category: Cybersecurity
Zero-Day, APT, Exfiltration, Lateral-Movement, Privilege-Escalation, Botnet, Rootkit, Backdoor, Keylogger, Smishing, Vishing, Spear-Phishing, Social-Engineering, MITM, SQL-Injection, XSS, CSRF, Path-Traversal, Buffer-Overflow, Honeypot, CVE, CVSS, Red-Team, Blue-Team, Threat-Hunting, Malware-Analysis, MITRE-ATT&CK, Insider-Threat, Jailbreak, Shellcode, Exploit-Kit, LFI, RFI, Obfuscation, Payload, security advisory, vulnerability disclosure, CWE, OWASP, cybersecurity news, threat intelligence, SOC, SIEM, cryptotheft, evasion, CVE Security
Cisco Issues Emergency Fix for Firewall Zero-Day Under Active Attack
Cisco has issued an urgent warning to organizations worldwide following the discovery of a zero-day vulnerability in its core firewall software. Tracked as CVE-2026-20349, the flaw is currently being exploited in the wild, allowing unauthenticated attackers to trigger a denial-of-service (DoS) condition. Because this vulnerability affects the perimeter of the network—the very place designed to keep threats out—security teams are
Critical Adobe Commerce Flaws Put Online Stores at Risk — Patch Now
Adobe has rolled out an urgent August 2026 security update for Adobe Commerce and Magento Open Source to fix a cluster of authorization and stored cross-site scripting (XSS) flaws that, together, present a significant threat to e-commerce environments. The most severe issue, CVE-2026-71362, is an incorrect-authorization vulnerability rated 9.1 (CVSS) that could allow an unauthenticated attacker to escalate privileges and
2.86 Billion Credentials Flood Criminal Markets — How Infostealers and Initial-Access Brokers Are Reshaping Risk
Stolen login data has become a commodity so abundant that it’s now cheap to buy in bulk — and alarmingly effective when attackers use it to pivot into corporate environments. In 2025, researchers reported roughly 2.86 billion compromised credentials traded across underground markets. That scale changes the calculus of identity: a correct username and password no longer prove much when
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
A newly disclosed critical flaw in VMware vCenter (CVE-2026-59310) has moved quickly from patch release to active exploitation, according to investigative reporting and telemetry from security firms. The vulnerability—a directory traversal bug that allows an actor with network access to execute arbitrary code—was patched by Broadcom late last month, and forensic evidence collected by QUIRSO indicates attackers were able to
Ransomware Strikes Colombian Justice Ministry Ahead of Presidential Transition
Colombia’s Ministry of Justice was hit by a ransomware attack on August 2, affecting parts of its IT infrastructure and degrading several public-facing services just days before a national presidential handover. The disruption touched systems used for illicit-drug monitoring and legal processes; while some files were encrypted, the acting minister at the time, Cielo Rusinque, said publicly that there was





