Skip to content
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Ravie LakshmananAug 25, 2026Vulnerability / Web Security Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker… 

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

Ravie LakshmananAug 25, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities… 

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Ravie LakshmananAug 24, 2026Malware / SEO Poisoning Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it… 

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used… 

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account

Swati KhandelwalAug 24, 2026Vulnerability / Identity Security Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated… 

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Ravie LakshmananAug 24, 2026Cyber Espionage / Cyber Attack Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation… 

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are…