Frost
-
Browser-based FROST attack can infer site visits from SSD timing
Researchers at Graz University of Technology say a browser-based attack called FROST can infer site visits and app launches from SSD timing, reaching 88.95% accuracy in one macOS test and working without native code or a permission prompt.
-
Critical Sneeit WordPress plugin RCE actively exploited, security firm reports
A critical remote code execution flaw (CVE-2025-6389) in the Sneeit Framework WordPress plugin is being exploited in the wild; Wordfence said attackers have created admin accounts and uploaded web shells. The issue affects versions up to 8.3 and was fixed in 8.4. Separately, VulnCheck observed an ICTBroadcast exploit delivering a DDoS botnet called “frost.”


