A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious ...
Ghost CMS SQL injection campaign has compromised 700+ websites — including Harvard University, Oxford University, and DuckDuckGo — using a CVSS 9.4 flaw to inject ClickFix malware lures that trick ...
In its warning, Drupal said a vulnerability in this API allows an attacker to send specially crafted requests resulting in ...
Nisarga Adhikary, a 19-year-old ethical hacker, has sparked fresh controversy around CBSE's digital systems after claiming he ...
Avada Flaw Widens Wordpress Security Risk Arabian Post. clearfix>Two vulnerabilities in the Avada Builder plugin have exposed around one million WordPress websites to attacks that could reveal ...
Drupal released security updates for a highly critical Drupal Core vulnerability affecting sites that use PostgreSQL.
New research highlights how AI-driven exploitation, zero-click vulnerabilities, and fragmented ransomware operations are reshaping cyber riskBOSTON, May 21, 2026 (GLOBE NEWSWIRE) -- Rapid7, Inc.
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days ...
Shannon Lite, the autonomous white-box penetration testing tool built by San Francisco-based Keygraph, shipped version 1.2.0 ...
A critical-level flaw in a popular CMS, patched months ago, is now being abused.
India's software supply chain security challenge is deepening as AI expands the attack surface while many enterprises lack ...
A popular WordPress plugin was found carrying two flaws that can cause data leaks.