Security news.
Today's security landscape highlights critical vulnerabilities across widely used software and platforms, from WordPress plugins to enterprise AI systems, demanding immediate patching. We also see major data breaches affecting large organizations like McKesson and Hasbro, alongside CISA's continued efforts to track actively exploited flaws.
Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple severe vulnerabilities, including authentication bypass and RCE, have been found in popular WordPress plugins like WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP.
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical giant McKesson revealed a cybersecurity incident, with the ShinyHunters extortion group claiming to have stolen 284 million patient records through unauthorized access to third-party applications.
Hasbro Data Breach Exposed Employee Personal Information
Toy and game giant Hasbro has disclosed a data breach following a cyberattack earlier this year, which exposed personal and financial information of an undisclosed number of employees.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added CVE-2023-49105 (ownCloud Improper Authentication), CVE-2026-53362 (Linux Kernel Unspecified Vulnerability), and CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname) to its KEV catalog due to active exploitation.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A critical balance-handling flaw (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20-25, affecting versions = 0.
PaperCut Releases Second Emergency Patch for Exploited Flaws
PaperCut has issued a second emergency security update for actively exploited vulnerabilities in its NG and MF print management software, addressing bypasses discovered in earlier fixes.
TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion
Microsoft Threat Intelligence details the "TerminalFix" campaign, which uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel in a multistage intrusion.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has patched four security flaws in its AI Platform, with three rated 10.0 CVSS, which could allow unauthenticated code execution and SQL injection under certain conditions.