A vulnerability was found in Themeum Tutor LMS Plugin up to 3.9.4 on WordPress and classified as critical . This vulnerability affects unknown code. The manipulation results in authorization bypass. T…
cyberintel.kalymoon.com · 53763 articles · updated every 4 hours · grows forever
A vulnerability was found in Themeum Tutor LMS Plugin up to 3.9.4 on WordPress and classified as critical . This vulnerability affects unknown code. The manipulation results in authorization bypass. T…
A vulnerability was found in tagDiv Composer Plugin up to 5.4.2 on WordPress. It has been classified as problematic . This issue affects some unknown processing. This manipulation causes cross site sc…
A vulnerability was found in Themeton Zuut Plugin up to 1.4.2 on WordPress. It has been declared as critical . Impacted is an unknown function. Such manipulation leads to deserialization. This vulnera…
A vulnerability was found in tagDiv Opt-In Builder Plugin up to 1.7.3 on WordPress. It has been rated as problematic . The affected element is an unknown function. Performing a manipulation results in…
A vulnerability categorized as critical has been discovered in Themeton Finag Plugin up to 1.5.0 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to deseria…
A vulnerability identified as critical has been detected in ThimPress BuilderPress Plugin up to 2.0.1 on WordPress. This affects an unknown function. The manipulation leads to improper control of file…
A vulnerability labeled as problematic has been found in Dotstore Fraud Prevention for Woocommerce Plugin up to 2.3.3 on WordPress. This impacts an unknown function. The manipulation results in missin…
A vulnerability marked as critical has been reported in Syarif Mobile App Editor Plugin up to 1.3.1 on WordPress. Affected is an unknown function. This manipulation causes unrestricted upload. This vu…
A vulnerability described as problematic has been identified in ThemeHunk Gutenberg Blocks Plugin up to 1.2.8 on WordPress. Affected by this vulnerability is an unknown functionality. Such manipulatio…
A vulnerability classified as critical has been found in Membership WishList Member X Plugin up to 3.29.0 on WordPress. Affected by this issue is some unknown functionality. Performing a manipulation …
A vulnerability classified as problematic was found in QantumThemes Kentha Plugin up to 4.7.2 on WordPress. This affects an unknown part. Executing a manipulation can lead to cross site scripting. The…
A vulnerability, which was classified as problematic , has been found in HCL Connections 8 . This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability…
A vulnerability, which was classified as problematic , was found in Ryan Howard Website LLMs.txt Plugin up to 8.2.6 on WordPress. This issue affects some unknown processing. The manipulation results i…
A vulnerability has been found in WPEverest Everest Forms Pro Plugin up to 1.9.10 on WordPress and classified as problematic . Impacted is an unknown function. This manipulation causes cross site scri…
Unit 42 research explores how AI is currently used in malware, from superficial integrations to advanced decision-making, and its future impact. The post Analyzing the Current State of AI Use in Malwa…
A threat actor with ties to Iran has had their entire working infrastructure exposed after carelessly leaving an open directory on their own staging server, handing researchers a rare look into a live…
A popular code editor extension listed on the Open VSX registry was discovered carrying hidden malware that silently fetches and runs a remote access trojan (RAT) and a full infostealer directly onto …
35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs
Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says
The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer
Multi-factor authentication was supposed to be the solution. For years, security teams have told employees that MFA would keep them safe. Password stolen? No problem — attackers still need that second…
Last year, most businesses faced a cloud security incident. Here’s what stands out — it wasn’t sophisticated cybercriminals behind these events. Instead, basic errors opened the door. According to the…
RSA Conference 2026 arrives at a significant inflection point for the cybersecurity industry — one that will see its more than 43,000 attendees and 600-plus exhibitors navigating an agenda that has fu…
Samba 4.24.0 arrived carrying a set of Kerberos security changes aimed at Active Directory deployments. The release fixes a vulnerability, extends audit coverage for sensitive AD attributes, and intro…