Security news.
Today's cybersecurity landscape is marked by widespread exploitation and significant regulatory actions. WordPress sites are under attack via critical authentication bypass flaws, while CISA has ordered urgent patching for actively exploited vulnerabilities in Zimbra and Oracle products. In other news, TikTok has agreed to a substantial settlement with the U.S. over alleged COPPA violations.
Hackers Exploit miniOrange SAML Plugin in WordPress
Threat actors are actively targeting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin, allowing them to forge SAML responses and gain administrator access.
CISA Adds Oracle HTTP Server Flaw to KEV Catalog
CISA has added an Improper Access Control vulnerability (CVE-2026-21962) in Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in to its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch.
CISA Mandates Patching for Actively Exploited Zimbra Flaw
U.S. government agencies have been ordered by CISA to patch an actively exploited OS Command Injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) within three days.
Critical Keycloak Password Reset Flaw Patched
Red Hat and the Keycloak project have released patches for CVE-2026-18963, a critical flaw allowing unauthenticated attackers to reset passwords and take over any user account in the open-source identity and access management server.
TikTok Settles COPPA Violations for $400M
TikTok, ByteDance, and affiliated companies have reached a $400 million settlement with the U.S. Department of Justice over allegations of violating the Children's Online Privacy Protection Act (COPPA).
ReliaQuest Confirms ShinyHunters Breach, Limited Impact
Cybersecurity firm ReliaQuest confirmed a phishing attack that compromised an employee's dashboard, with threat group ShinyHunters claiming responsibility, though the company states the impact was limited.
Tricky 'SynkLoader' Malware Emerges, May Herald Ransomware
A sophisticated, multilingual malware family named 'SynkLoader' has been identified, bringing back screen hijacking for password theft and featuring novel functionalities that could precede ransomware deployments.
ToxicPanda Banking Trojan Evolves into Enterprise Threat
The latest version of the ToxicPanda Android malware includes new features that expand its global reach and now poses a broader risk to enterprise users beyond just financial applications.