News
-
CISA adds exploited Magento extension flaw to known vulnerabilities list
CISA added a critical Magento extension flaw to its exploited vulnerabilities catalog after reports of active abuse. The bug, CVE-2026-45247, can allow remote code execution and affects versions of Mirasvit Cache Warmer before 1.11.12.
-
Google patches Gemini flaw that could let poisoned notifications trigger Android actions
Google patched a Gemini on Android flaw that let a poisoned notification influence the assistant, potentially triggering actions from fake messages to smart home controls. SafeBreach said the bug was fixed server-side and no in-the-wild abuse was found.
-
CISA warns of cyberattacks targeting fuel tank monitoring systems
CISA warned on June 3 that cyberattacks are targeting fuel tank monitoring systems used in critical infrastructure. The report did not identify the attackers or say whether the activity caused outages or damage.
-
One-click VS Code attack can steal GitHub tokens from GitHub.dev
A technical analysis says a one-click attack against GitHub.dev in VS Code can steal a GitHub token with access to private repositories. Microsoft has acknowledged the issue and said it is working on a fix.
-
Researchers find HTTP/2 flaw that can trigger rapid denial of service on major servers
Researchers say a new HTTP/2 denial-of-service flaw can hit major web servers, including NGINX, Apache HTTPD and Microsoft IIS. The issue can rapidly exhaust memory and may be difficult to block in default configurations.
-
Critical Kirki flaw lets attackers take over WordPress admin accounts
Hackers are exploiting a critical flaw in the Kirki WordPress plugin to hijack user accounts, including admins, with more than 222 attack attempts blocked in 24 hours, according to Wordfence.
-
WeedHack malware campaign infects more than 116,000 Minecraft systems
A malware campaign called WeedHack has infected more than 116,000 Minecraft systems since January, using fake mods and clients promoted through YouTube and search poisoning to steal credentials and other data.
-
WordPress WP Maps Pro flaw under active attack, 2,858 attempts blocked
A critical WP Maps Pro flaw is being actively exploited to create WordPress administrator accounts, with Wordfence blocking 2,858 attacks in 24 hours. The issue affects versions through 6.1.0 and was fixed in 6.1.1.
-
Palo Alto PAN-OS flaw under active exploitation as limited attacks reported
Palo Alto Networks said an authentication bypass in PAN-OS and Prisma Access is under active exploitation, with limited attempts seen against unpatched devices. The flaw can let attackers establish unauthorized VPN connections.
-
ChatGPhish flaw can turn ChatGPT summaries into phishing lures
Researchers disclosed ChatGPhish, a ChatGPT flaw that can render malicious links, images and QR codes inside summaries of web pages. The technique may leak browser details and create a new phishing surface during normal browsing.









