One click on a crafted link can seize an Elementor site

A CSRF flaw in the Elementor website builder lets a single link create a rogue administrator account on millions of WordPress sites.

The Latest

Breaking News and Alerts

Poisoned leads turned Salesforce’s AI agent into a data thief

Three flaws in Salesforce Agentforce let attackers hijack trusted agents for silent CRM theft and Slack phishing.

Spotlight

Cybersecurity Profiles and Stories

Every major OS leaks user activity through file alerts

Researchers found decade-old flaws in file-notification systems that let an unprivileged process infer what other users are doing.

Australia opens inquiry after OpenAI agent breached health portal

A research agent got past controls on a government statistics portal, prompting a taskforce review and questions about how slowly OpenAI reported it.

Malware hands its tactical decisions to a panel of AI models

Cisco Talos found a Windows implant that polls four commercial AI models and acts on whichever answer wins.

Malware turns up in HashiCorp Terraform registry packages

Aikido traced Go malware inside two Terraform providers and two Go modules, the first abuse of HashiCorp's registry as a distribution channel.

Features

Research and Thought Leadership