GitLab AI Agent Flaw Could Expose CI Pipelines
GitLab has released security updates for a high-severity vulnerability in its Duo Claude AI agent that could allow authenticated developers to run unauthorized commands inside CI pipeline environments. Tracked as [...]
Patch Now: Critical Next.js Flaw Enables RCE
Two critical security issues in Next.js could allow attackers to execute code remotely on vulnerable applications without logging in. The first vulnerability, CVE-2026-75604, affects applications using the Image Optimization API [...]
WordPress Plugin Flaw Puts 400,000 Sites at Risk
A critical security flaw in the TranslatePress WordPress plugin could allow attackers to take control of administrator accounts without needing to log in first. Tracked as CVE-2026-19632, the vulnerability affects [...]
npm Packages Exploited for ClickFix Phishing
Security researchers have uncovered a campaign involving 24 malicious npm packages that use legitimate package-mirroring services to deliver phishing content. The attackers are not primarily interested in getting developers to [...]
Hackers Target ASOS Accounts Using Stolen Login Credentials
ASOS US Sales LLC has warned customers about unauthorized access to some accounts after attackers used login credentials obtained from outside the company. The activity was detected on July 28, [...]