Ad image

WordPress Plugin Flaw Lets Attackers Take Over Sites via Admin Creation

Attackers are exploiting a privilege escalation bug in the WP Maps Pro WordPress plugin to create unauthorized administrator accounts on vulnerable websites.

The Latest

Breaking News and Alerts

ChatGPT Summary Feature Exploited to Deliver Phishing Payloads

Researchers show that adding malicious Markdown payloads to web pages can trick ChatGPT into serving phishing links, fake alerts, and QR codes within its trusted interface.

Spotlight

Cybersecurity Profiles and Stories

Google Engineer Charged for Using Confidential Data to Win Big on Prediction Market

Michele Spagnuolo used internal Google 'Year in Search' data to win $1.2 million on Polymarket, leading to federal charges for insider trading.

Unpatched Flaw in Gogs Git Service Opens Door to Remote Attackers

A newly disclosed argument injection flaw in the Gogs self-hosted Git service allows authenticated attackers to execute arbitrary code on exposed servers, with no patch yet available from maintainers.

Why MSPs Are Turning to Unified SIEM to Cut Through Alert Noise

Unified SIEM platforms help MSPs correlate fragmented security signals into a single incident narrative, cutting investigation time and reducing alert fatigue.

From Scripts to Subscriptions: The Rise of DDoS as a Service

The DDoS for hire market has evolved from scattered scripts to polished commercial platforms with subscription plans, botnet powered infrastructure, and customer support, making disruption accessible to anyone with a…

Features

Research and Thought Leadership