Below I’ve curated cyber security news from the world-wide-web – the lefthand column is from “The Hacker News” website and on the right is news from “Security Week”. Both are top cyber security news sites. In the very least this shows that threats are daily and they are very real.
Hacker News
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+...by info@thehackernews.com (The Hacker News) on May 25, 2026 at 12:02 pm
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in […]
- The Alert Firehose Finally Meets Its Matchby info@thehackernews.com (The Hacker News) on May 25, 2026 at 11:30 am
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase fewer false […]
- Lazarus Deploys RemotePE Memory-Only RAT Against...by info@thehackernews.com (The Hacker News) on May 25, 2026 at 9:32 am
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain […]
- TrapDoor Supply Chain Attack Spreads...by info@thehackernews.com (The Hacker News) on May 25, 2026 at 5:59 am
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, […]
- npm Adds 2FA-Gated Publishing and Package Install...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 4:35 pm
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on […]
- Packagist Supply Chain Attack Infects 8 Packages...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 4:07 pm
A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," […]
- Claude Mythos AI Finds 10,000 High-Severity Flaws...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 11:55 am
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive […]
- Laravel-Lang PHP Packages Compromised to Deliver...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 9:51 am
Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses […]
- LiteSpeed cPanel Plugin CVE-2026-48172 Exploited...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 7:35 am
A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary […]
- Drupal Core SQL Injection Bug Actively Exploited,...by info@thehackernews.com (The Hacker News) on May 23, 2026 at 7:23 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-9082 (CVSS score: […]
WordPress News
- WordPress 7.0 “Armstrong”by Matias Ventura on May 20, 2026 at 6:41 pm
Explore AI abilities directly in your website, all managed from a central hub. Slide seamlessly through the sleek, new admin theme implemented across the dashboard. Ignite creative flow with new blocks and design tools, and tap into an expansive developer toolbox that gives you more control than […]
- WordPress 7.0 Release Candidate 4by Amy Kamala on May 14, 2026 at 4:47 pm
The fourth Release Candidate (“RC4”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- Get Your WordCamp US 2026 Ticketsby Brett McSherry on May 14, 2026 at 1:56 pm
August 16–19, 2026, Phoenix Convention Center – Phoenix, Arizona Tickets are now available for WordCamp US 2026, taking place August 16–19, 2026, at the Phoenix Convention Center in Phoenix, Arizona. The flagship event brings together people from across the WordPress community to learn, […]
- WordPress 7.0 Release Candidate 3by Amy Kamala on May 8, 2026 at 6:18 pm
The third Release Candidate (“RC3”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- Get Involved With WordCamp US 2026 in Phoenixby Brett McSherry on May 4, 2026 at 6:10 pm
WordCamp US 2026 will take place August 16–19 in Phoenix, Arizona, and applications are now open for sponsors, speakers, and volunteers. WordCamp US is the flagship gathering for the WordPress community in North America, where contributors, builders, and users come together to share ideas and […]
- WordPress Student Clubs Build Momentumby Brett McSherry on April 29, 2026 at 1:14 pm
WordPress Student Clubs are beginning to take shape as a new way to carry the momentum of WordPress Campus Connect beyond one-time workshops. What starts as an introduction to WordPress and open source is now continuing on campus through student-led groups that create space for learning, peer […]
- Celebrating Community at WordCamp Asia 2026by Brett McSherry on April 11, 2026 at 6:21 pm
WordCamp Asia 2026 brought the global WordPress community to Mumbai, India, from April 9–11, gathering contributors, organizers, sponsors, speakers, and attendees at the Jio World Convention Centre for three days of learning, collaboration, and community. With 2,627 attendees, the event reflected […]
- How to Watch WordCamp Asia 2026 Liveby Brett McSherry on April 7, 2026 at 1:57 pm
WordCamp Asia 2026 will be available to watch live across three days of streaming, making it easy for the global WordPress community to follow along from anywhere. This year’s live streamed programming begins with a special Contributor Day broadcast, followed by two full conference days of […]
- From AI to Open Source at WordCamp Asia 2026by Brett McSherry on April 2, 2026 at 4:10 pm
April 9-11, 2026 | Jio World Convention Centre, Mumbai, India WordCamp Asia 2026 brings the WordPress community to Mumbai, India, from April 9 to 11, with a schedule shaped around artificial intelligence, enterprise WordPress, developer workflows, product strategy, and open source collaboration. […]
- WordPress 7.0 Release Candidate 2by Mary Hubbard on March 26, 2026 at 6:37 pm
The second Release Candidate (“RC2”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]

















