WordPress Plugin Unauthenticated Admin Access Vulnerability Discovered
A critical WordPress plugin unauthenticated admin access vulnerability has been discovered in the User Registration & Membership plugin, allowing attackers to create administrator accounts. The vulnerability, tracked as CVE-2026-1492, affects [...]
ClickFix Malware Targets Crypto Experts via Fake LinkedIn VCs
Security researchers have uncovered a coordinated malware campaign targeting people working in the cryptocurrency and Web3 industry. Attackers pretend to be venture capital investors on LinkedIn and approach professionals with [...]
Fake LastPass Support Scam Targets Password Vaults
A new phishing campaign is pretending to be LastPass support emails to trick users into revealing their vault passwords and account credentials. Attackers send emails that look like internal support [...]
OAuth Phishing Campaign Targets Entra ID and Google Workspace
Microsoft has discovered advanced phishing campaigns that misuse the normal behavior of the OAuth 2.0 authentication process. Instead of exploiting software bugs or directly stealing passwords, attackers abuse trusted login [...]
Chrome Introduces Quantum-Safe HTTPS Protection
Google Chrome’s security team has announced a new plan to protect HTTPS from future quantum computer attacks. The new approach uses Merkle Tree Certificates (MTCs), developed through the IETF PLANTS [...]