Below I’ve curated cyber security news from the world-wide-web – the lefthand column is from “The Hacker News” website and on the right is news from “Security Week”. Both are top cyber security news sites. In the very least this shows that threats are daily and they are very real.
Hacker News
- Developer Workstations Are Now Part of the...by info@thehackernews.com (The Hacker News) on May 18, 2026 at 11:23 am
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer […]
- Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL...by info@thehackernews.com (The Hacker News) on May 18, 2026 at 10:54 am
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be […]
- MiniPlasma Windows 0-Day Enables SYSTEM Privilege...by info@thehackernews.com (The Hacker News) on May 18, 2026 at 8:57 am
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the […]
- Four Malicious npm Packages Deliver Infostealers...by info@thehackernews.com (The Hacker News) on May 18, 2026 at 8:57 am
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) […]
- Pre-Stuxnet Fast16 Malware Tampered with Nuclear...by info@thehackernews.com (The Hacker News) on May 18, 2026 at 6:46 am
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations […]
- NGINX CVE-2026-42945 Exploited in the Wild,...by info@thehackernews.com (The Hacker News) on May 17, 2026 at 11:57 am
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module […]
- Grafana GitHub Token Breach Led to Codebase...by info@thehackernews.com (The Hacker News) on May 17, 2026 at 7:13 am
Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this incident, and we have […]
- Funnel Builder Flaw Under Active Exploitation...by info@thehackernews.com (The Hacker News) on May 16, 2026 at 3:20 pm
A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by […]
- Turla Turns Kazuar Backdoor Into Modular P2P...by info@thehackernews.com (The Hacker News) on May 15, 2026 at 5:10 pm
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security […]
- Four OpenClaw Flaws Enable Data Theft, Privilege...by info@thehackernews.com (The Hacker News) on May 15, 2026 at 1:35 pm
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose […]
WordPress News
- WordPress 7.0 Release Candidate 4by Amy Kamala on May 14, 2026 at 4:47 pm
The fourth Release Candidate (“RC4”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- Get Your WordCamp US 2026 Ticketsby Brett McSherry on May 14, 2026 at 1:56 pm
August 16–19, 2026, Phoenix Convention Center – Phoenix, Arizona Tickets are now available for WordCamp US 2026, taking place August 16–19, 2026, at the Phoenix Convention Center in Phoenix, Arizona. The flagship event brings together people from across the WordPress community to learn, […]
- WordPress 7.0 Release Candidate 3by Amy Kamala on May 8, 2026 at 6:18 pm
The third Release Candidate (“RC3”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- Get Involved With WordCamp US 2026 in Phoenixby Brett McSherry on May 4, 2026 at 6:10 pm
WordCamp US 2026 will take place August 16–19 in Phoenix, Arizona, and applications are now open for sponsors, speakers, and volunteers. WordCamp US is the flagship gathering for the WordPress community in North America, where contributors, builders, and users come together to share ideas and […]
- WordPress Student Clubs Build Momentumby Brett McSherry on April 29, 2026 at 1:14 pm
WordPress Student Clubs are beginning to take shape as a new way to carry the momentum of WordPress Campus Connect beyond one-time workshops. What starts as an introduction to WordPress and open source is now continuing on campus through student-led groups that create space for learning, peer […]
- Celebrating Community at WordCamp Asia 2026by Brett McSherry on April 11, 2026 at 6:21 pm
WordCamp Asia 2026 brought the global WordPress community to Mumbai, India, from April 9–11, gathering contributors, organizers, sponsors, speakers, and attendees at the Jio World Convention Centre for three days of learning, collaboration, and community. With 2,627 attendees, the event reflected […]
- How to Watch WordCamp Asia 2026 Liveby Brett McSherry on April 7, 2026 at 1:57 pm
WordCamp Asia 2026 will be available to watch live across three days of streaming, making it easy for the global WordPress community to follow along from anywhere. This year’s live streamed programming begins with a special Contributor Day broadcast, followed by two full conference days of […]
- From AI to Open Source at WordCamp Asia 2026by Brett McSherry on April 2, 2026 at 4:10 pm
April 9-11, 2026 | Jio World Convention Centre, Mumbai, India WordCamp Asia 2026 brings the WordPress community to Mumbai, India, from April 9 to 11, with a schedule shaped around artificial intelligence, enterprise WordPress, developer workflows, product strategy, and open source collaboration. […]
- WordPress 7.0 Release Candidate 2by Mary Hubbard on March 26, 2026 at 6:37 pm
The second Release Candidate (“RC2”) for WordPress 7.0 is ready for download and testing! This version of the WordPress software is under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended that you […]
- WP Packages is Working the Way Open Source Shouldby Jonathan Bossenger on March 25, 2026 at 3:27 pm
When WP Engine acquired WPackagist on March 12, the WordPress developer community faced a familiar question: what happens when critical open source infrastructure ends up under corporate control? The community already had an answer in progress. Four days later, WP Packages (formerly WP Composer) […]
















