Two WordPress plugins have taken over 440,000 exploit attempts between them. Here’s a plain-English breakdown of what happened and the checklist to run on your own site.
News
-
-
Attackers are exploiting a MikroTik RouterOS flaw with no password needed. Here’s exactly how to check whether your router is already compromised and what to do about it.
-
TerminalFix’s exotic technical detail hides a simpler truth: a fake CAPTCHA still works, and what decides the outcome is whether anyone notices what happens after the click.
-
Researchers found Aurora ransomware affiliates using the Cursor AI coding assistant to plan and run intrusions against at least ten organisations, exploiting the same Active Directory weaknesses pen testers have …
-
CVE-2026-9586 shows how a mundane coding mistake in Sangoma’s Switchvox platform exposed thousands of businesses that never patch their phone systems.
-
SonicWall’s second exploited SMA zero-day chain this year is a reminder that perimeter VPN appliances need testing and hardening, not just a patch cycle.
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.
-
TikTok’s $400 million COPPA settlement points to specific, checkable failures. Here’s how UK businesses can audit their own child data compliance before a regulator asks.
-
Have I Been Pwned onboarded Sri Lanka CERT as its 48th free government subscriber. For UK businesses, the story is about who watches your exposed staff logins, and what they …
-
Five WordPress plugins and themes were hit by critical, no-login-required flaws this week. Here is a plain checklist for checking your own site, whether you run any of them or …