Cybersecurity
Curated coverage and analysis in this editorial area.

Five Critical Flaws Hit WordPress Plugins and Theme: The GiveWP Case
WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP contain CVSS 9.8–10.0 vulnerabilities enabling unauthenticated site takeov…

AI Kill Switch Act: The Red Button Is Law, But Does It Work?
The bipartisan AI Kill Switch Act requires developers to maintain the ability to shut down advanced AI systems. The distributed nature…

ZBT Routers Ship with Factory-Installed Implants: Unauthenticated Remote Root for Anyone
VulnCheck disclosed two factory-installed firmware implants in routers from Shenzhen Zhibotong Electronics (ZBT): SPEAKINGSTONE and DA…

BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services
The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site fo…

Bug in JavaScript Obfuscator Exposes Polymorphic Phishing Campaign
A server-side scope error in an obfuscator triggered infinite loops in 3.6% of variants, revealing a polymorphic evasion mechanism tha…

Next.js: Two Critical RCE Patches Expose the Managed vs. Self-Hosted Protection Gap
Vercel released critical patches for two unauthenticated RCE vulnerabilities in Next.js on August 25, 2026. The disparity in protectio…

PaperCut: Active Zero-Day Exploitation Confirmed Across All NG and MF Versions
PaperCut Software confirmed on August 27, 2026, that an undisclosed vulnerability affecting all versions of PaperCut NG and PaperCut M…

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab
The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…

ShinyHunters Inflates Carhartt Breach with Synthetic Data, but Real Count Is 12.9 Million
ShinyHunters published 50 GB of Carhartt data after the company refused a $3.3 million ransom. Troy Hunt's OpenClaw analysis exposed t…

ICS Isn't Safer — Just More Selective. Biometric Sector Remains Top Target
In Q2 2026, the global share of ICS computers with blocked malicious objects fell to 19.15%, the lowest since 2022. Yet the biometric…

GPUThor Bypasses NVIDIA ECC: Root Escalation in 1.1 Minutes on Workstation GPUs
The new GPUThor Rowhammer attack defeats SECDED ECC protection on NVIDIA Ampere RTX A4000-A6000 workstation cards. No patch is availab…

Hugging Face Kubernetes AI Agent Intrusion
Qualys mapped the stages of an autonomous AI agent's multi-day intrusion against Hugging Face's Kubernetes environment on July 9, 2026…