Apache ActiveMQ Vulnerability Enables DoS Attacks
Researchers have identified a security issue in Apache ActiveMQ, specifically related to the Apache ActiveMQ DoS vulnerability, a widely used open-source message broker that enables communication between applications. The vulnerability, [...]
WordPress Plugin Unauthenticated Admin Access Vulnerability Discovered
A critical WordPress plugin unauthenticated admin access vulnerability has been discovered in the User Registration & Membership plugin, allowing attackers to create administrator accounts. The vulnerability, tracked as CVE-2026-1492, affects [...]
ClickFix Malware Targets Crypto Experts via Fake LinkedIn VCs
Security researchers have uncovered a coordinated malware campaign targeting people working in the cryptocurrency and Web3 industry. Attackers pretend to be venture capital investors on LinkedIn and approach professionals with [...]
Fake LastPass Support Scam Targets Password Vaults
A new phishing campaign is pretending to be LastPass support emails to trick users into revealing their vault passwords and account credentials. Attackers send emails that look like internal support [...]
OAuth Phishing Campaign Targets Entra ID and Google Workspace
Microsoft has discovered advanced phishing campaigns that misuse the normal behavior of the OAuth 2.0 authentication process. Instead of exploiting software bugs or directly stealing passwords, attackers abuse trusted login [...]