A critical CVE-2026-32475 file upload bug in Elementor Pro exposes WordPress sites to unauthenticated remote code execution, with fixes in version 4.2.2.
Microsoft has spotted a finance-themed phishing wave that uses invisible Unicode tag characters to split lure keywords and sneak millions of emails past filters.
Frontier AI systems are automating multi-step cyberattacks, giving enterprises only months to accelerate patching, harden identity and govern AI use before attacks scale[7][8][12].
X is investigating a wave of unsolicited password-reset emails tied to its X Money rollout, with no breach confirmed but rising phishing risks for users.
Googleβs latest Chrome 152 update fixes 12 flaws, including CVE-2026-85046, a V8 type confusion zero-day, and urges users and enterprises to update fast.
G7 cyber experts issue roadmap urging financial institutions to begin migration to quantum-safe cryptography, aligning with NIST timelines and 2030s goals.
Fishing app Fishbrain has disclosed a July 2026 breach that exposed user personal data plus password hashes and salts, prompting a global reset of account logins.
A high-severity SQL injection in AllβinβOne WP Migration and Backup exposes millions of WordPress sites to unauthenticated remote code execution risk.
Thomson Reuters' C-Track court management platform was breached, exposing case records in 11 US states, the US Virgin Islands, Oregon and Canadian courts.