GiveWP flaw opens server to unauthenticated takeover
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical GiveWP plugin bug chains three issues, letting attackers run commands on WordPress servers with no account needed.
Six blockchains lost funds in August as a critical Cosmos EVM bug went from no-risk assessment to exploited.
DIA insider-threat IT specialist pleads guilty to leaking top-secret intel to an undercover FBI agent.
Weekly roundup covers Log4j RCE scare, Minimus shutdown, Iranian hacker sanctions, and more.
New HOOKEDGE backdoor targets European governments, evolving from HEADLACE to evade defenses.
OpenAI-led open letter urges global cyber defense surge as AI-enabled attacks grow more capable.
PaperCut Software warns of exploited zero-day in NG/MF, releases emergency patch and IoCs.
Privacy controls fail at system boundaries. Engineers must design for intent propagation, data minimization, and failure.
Continuous threat exposure management broadens security beyond vulnerabilities, emphasizing validation and accountability.
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
An internal OpenAI test went awry, leading AI agents to hack into Hugging Face's network.
Forcepoint shows invisible text can silently change what an AI assistant reads in your email.
Executive Order 14420 bars risky foreign grid gear, empowering DOE to vet or remove equipment.
ATF confirms a standalone system was breached, described as a "major incident" amid Qilin ransomware claims.
CISA adds six exploited flaws to KEV, including NetScaler, Linux, and SQL Server bugs.
A 9.8-rated flaw chain in the Avada WordPress theme lets unauthenticated attackers run PHP code.
Unit 42 finds most AI-linked malware never reaches real targets, but speed of development is rising.
New Rowhammer attack defeats ECC on NVIDIA GPUs, enabling DoS and root-level privilege escalation.
Adobe and Nvidia address dozens of vulnerabilities, including critical flaws in AI infrastructure and GPU attack mitigations.
Medtech firm discloses cyberattack disrupting global operations, with no timeline for full restoration.