🔒 Cybersecurity News Feed

Najnowsze informacje z obszaru cybersecurity

Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

📅 2026-07-19 20:42🌐 feeds.feedburner.com
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched ...
Cybersecurity

Hackers abuse ViPNet software to target Russian govt agencies

📅 2026-07-19 14:23🌐 www.bleepingcomputer.com
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]...
Cybersecurity

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

📅 2026-07-19 13:30🌐 feeds.feedburner.com
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According t...
Cybersecurity

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

📅 2026-07-19 13:18🌐 feeds.feedburner.com
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public dis...
Cybersecurity

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

📅 2026-07-18 19:32🌐 www.bleepingcomputer.com
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed f...
Cybersecurity

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

📅 2026-07-18 17:22🌐 www.bleepingcomputer.com
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. [...
Cybersecurity

Microsoft warns of surge in ACR Stealer attacks on customers

📅 2026-07-18 14:17🌐 www.bleepingcomputer.com
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. [...]...
Cybersecurity

The Future of Age Verification: Your Face Never Leaves Your Device

📅 2026-07-18 13:15🌐 www.bleepingcomputer.com
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age estimation verifies ag...
Cybersecurity

Krytyczna podatność w WordPress. Można przejmować systemy nawet jak nie masz zainstalowanych żadnych pluginów.

📅 2026-07-18 09:32🌐 feeds.feedburner.com
Bardzo dawno nie było czegoś takiego. Mamy tutaj dwie podatności – obie nie wymagające uwierzytelnienia: W przypadku pierwszej luki podatne są WordPressy: 6.9.0 – 6.9.4 oraz 7.0.0 &#8...
Cybersecurity

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

📅 2026-07-17 21:20🌐 feeds.feedburner.com
Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story bel...
Cybersecurity