News

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

More than 200,000 WordPress websites are potentially exposed to takeover attacks via two critical-severity vulnerabilities in The Events Calendar plugin. A highly popular plugin with over 600,000 active installations, The Events Calendar allows administrators to easily create and manage an events calendar on their websites. All plugin versions before 6.17.3.1 are affected by two code injection bugs that could lead to remote code execution (RCE), allowing attackers to take over sites, WordPress security firm Defiant…

Read More

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

Microsoft AI has published a draft “Humanist AI Code of Conduct” for its MAI Models, spelling out safety rules for offensive cyber capabilities, limits on autonomous AI agents, and a dedicated review track for cybersecurity and other specialized uses. According to the code of conduct, models are blocked from producing working exploit code, attack tooling, planning and targeting methodologies, intrusion procedures, evasion techniques, operational guidance, or other assistance that would enable or improve a cyberattack.…

Read More

Telus Warns Customers of Account Breaches

Telus, one of Canada’s largest telecom providers, is notifying some customers that their accounts have been breached and their personal information has been accessed. In data breach notifications sent to customers whose consumer telecom accounts were affected, Telus said the intrusions occurred between February 2025 and June 2026.  According to the company, the attacker used compromised credentials to access Telus accounts and the information they store, including names, account numbers, phone numbers, billing addresses, email…

Read More

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage groups have been using a new exploit kit dubbed BlueMoon in seemingly opportunistic and rushed deployments, cybersecurity firm Proofpoint reports. The China-linked APT Violet Typhoon (also tracked as APT31, JungleBamboo, TA412, and Tide Castle) was the first to use it on August 28. Within days, several other Chinese threat actors started using it, but the activity might not be exclusive to China-aligned groups. “It is currently unknown how multiple distinct threat actors obtained…

Read More

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic says Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to use the AI model to develop advanced missiles. AI is already transforming warfare from Ukraine to Gaza, and its use on a rugged and remote battlefield is likely to increase concerns about its rapid spread. Anthropic said the users of the accounts, which it blocked after identifying them, did not succeed in “fielding an operational device” but did carry out…

Read More

Mandiant Founder Kevin Mandia Joins Amazon Board

Amazon has appointed cybersecurity veteran Kevin Mandia to its board of directors, strengthening the technology giant’s security expertise at the board level. Mandia was elected to the board on September 8 and brings more than 30 years of experience responding to cyber threats across the public and private sectors, Amazon announced. He is the founder and CEO of cybersecurity firm Armadin and a co-founder and general partner at cybersecurity-focused venture capital firm Ballistic Ventures. Mandia is…

Read More

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches. Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop…

Read More

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate…

Read More

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched…

Read More

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for File Upload fields. The bug, tracked as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue…

Read More