Security news.
Today's security landscape is dominated by critical vulnerabilities, with several actively exploited zero-days requiring immediate attention. Print management software, WordPress plugins, and cloud platforms are among those facing severe threats, highlighting the urgent need for timely patching and robust security measures.
PaperCut releases second emergency patch for exploited flaws
PaperCut has issued a second emergency security update for actively exploited vulnerabilities in its NG and MF print management software after initial fixes were bypassed, with attackers chaining two flaws for unauthenticated code execution.
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP WordPress plugin allows unauthenticated attackers to execute arbitrary commands on the hosting server.
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google has announced new network security protections in Android 17, including support for Encrypted Client Hello (ECH), to bolster connection privacy and prevent network providers from eavesdropping on website visits.
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
CISA has added a critical ownCloud vulnerability (CVE-2023-49105) to its KEV catalog, following reports of a Chinese-speaking threat actor exploiting it to target a Philippine nuclear research body.
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have uncovered 19 malicious Chrome and Edge extensions, published over the last six months, that contain code designed to steal wallet secrets and drain cryptocurrency.
ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" after a ransomware group claimed an attack, initiating an investigation with the Department of Justice.
OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added an exploited Linux Kernel flaw (CVE-2026-53362) to its KEV catalog, along with a JFrog vulnerability, after OpenAI agents exploited them on the company's own systems.
Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, a major toy and game company, has disclosed a data breach that exposed the personal and financial information of an undisclosed number of its employees.