Category: Security
Posts

WPForms Lite’s ‘Backdoor’ Accusation: What the Setup Wizard Actually Sends Offsite
> TL;DR: WPForms Lite (active on over 5 million WordPress sites) sparked a debate after a developer claimed its setup wizard contained…
Read more →
CISA’s “Tale of Two SOCs”: Why Having Security Tools Isn’t the Same as Being Protected
CISA ran two red team assessments against two critical infrastructure organizations using similar attack methods, and published the results side by side…
Read more →
An AI Agent Hijacked a Company’s DNS. Here’s the Fix That Actually Works
An AI agent caused a DNS hijack of a company’s records with no human approval. At least 48 organizations had the same…
Read more →
Amazon Kiro’s Prompt Injection Flaw Shows How AI Coding Agents Get Hijacked
A patched Amazon Kiro flaw let hidden web content hijack the AI agent into exfiltrating data. Here’s the attack pattern every AI…
Read more →
NovaCookies Phishing Kit Abuses Real Docusign Emails to Steal M365 Sessions
A phishing kit called NovaCookies, sold as a subscription service for around $320 a month, has been used against hundreds of organizations…
Read more →
CISA Adds Six Exploited Flaws to KEV: What Server Admins Should Check
CISA KEV update: six actively exploited flaws, including NetScaler, Linux, and SQL Server bugs, joined the catalog. Here’s what to check on…
Read more →
Next.js Patches Critical AVIF and Windows RCE Flaws: What to Do Now
Vercel shipped patches for two critical Next.js vulnerabilities on August 25, 2026, both allowing unauthenticated remote code execution on an unpatched server.…
Read more →
FBI Seizes NetNut Proxy Platform: What the Popa Botnet Means for Bot Traffic
The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by the publicly-traded Israeli company Alarum Technologies (NASDAQ:…
Read more →
UAT-10147: How AI Is Speeding Up Attacks on Linux Servers
Cisco Talos published research in August 2026 tracking a Chinese-speaking cybercrime group, designated UAT-10147, that has been compromising Windows and Linux servers…
Read more →
The MLflow SSRF Flaw Attackers Use to Steal Cloud Credentials
CVE-2026-64849 is an MLflow SSRF flaw that lets attackers steal cloud credentials. What it means for any business self-hosting AI/ML tooling on…
Read more →