Below I’ve curated cyber security news from the world-wide-web – the lefthand column is from “The Hacker News” website and on the right is news from “Security Week”. Both are top cyber security news sites. In the very least this shows that threats are daily and they are very real.
Hacker News
- CISA Flags Actively Exploited Ray Flaw That Can...by info@thehackernews.com (The Hacker News) on August 18, 2026 at 6:34 am
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale […]
- Critical GitLab GraphQL Flaw Could Let...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 9:03 pm
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked […]
- Snowflake GitHub Actions Flaw Lets Crafted Issues...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 6:44 pm
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira […]
- Forminator WordPress Flaw Can Enable...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 6:22 pm
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS […]
- Cavern C2 Uses DNS and Google Apps Script to...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 5:41 pm
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity […]
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day,...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 1:23 pm
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was […]
- How MCP Servers Can Expose Enterprise Secretsby info@thehackernews.com (The Hacker News) on August 17, 2026 at 11:58 am
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP […]
- Unisoc VoLTE Video Call Exploit Chain Can Give...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 10:52 am
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of […]
- Evooo1Bot Linux Botnet Exploits Known Flaws to...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 9:29 am
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the […]
- Suspected China-Nexus Actor Exploits VMware...by info@thehackernews.com (The Hacker News) on August 17, 2026 at 7:36 am
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability […]
WordPress News
- Introducing the WordPress Browser Extensionby Jake Goldman on August 13, 2026 at 4:29 pm
The official WordPress Browser Extension is now available for Google Chrome and Chromium-based browsers in the Chrome Web Store and for Safari on macOS in the Mac App Store. This new open source extension lets logged-in site users easily hide the admin bar while keeping its most helpful shortcuts […]
- WordPress 7.0.4 Releaseby John Blackbourn on August 12, 2026 at 2:45 pm
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard […]
- WordPress 7.0.3 releaseby John Blackbourn on August 6, 2026 at 6:55 pm
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s […]
- WordPress 7.1 Release Candidate 1by Benjamin Zekavica on August 5, 2026 at 3:37 pm
The first Release Candidate (“RC1”) for WordPress 7.1 is ready for download and testing! This version of the WordPress software is still under development. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, it’s recommended to […]
- WordPress 7.1 Beta 4by Benjamin Zekavica on July 29, 2026 at 3:30 pm
WordPress 7.1 Beta 4 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new […]
- WordPress 7.1 Beta 3by Benjamin Zekavica on July 22, 2026 at 3:23 pm
WordPress 7.1 Beta 3 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new […]
- WordPress 7.0.2 Releaseby John Blackbourn on July 17, 2026 at 6:45 pm
WordPress 7.0.2 is now available. The 7.0.2 security release addresses one critical and one high severity security issue. Because this is a security release, it is recommended that you update your sites immediately. Due to the severity, the WordPress.org team have enabled forced updates via the […]
- WordPress 7.1 Beta 1by Krupa Nanda on July 15, 2026 at 3:53 pm
WordPress 7.1 Beta 1 is ready for download and testing! This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new […]
- Your Guide to WordCamp US 2026by Nicholas Garofalo on July 13, 2026 at 1:07 pm
WordCamp US 2026 returns for another year, this time in Phoenix, Arizona, for four days, August 16 to 19. It comes at a moment of real energy for WordPress, as artificial intelligence reshapes everyday workflows, the business of building and maintaining sites is shifting, and new people keep […]
- WordPress 7.0.1 Maintenance Releaseby Estela Rueda on July 9, 2026 at 5:33 pm
WordPress 7.0.1 is now available! This minor release includes fixes for 31 bugs throughout Core and the Block Editor, addressing issues affecting multiple areas of WordPress including the block editor, admin ui, and media. For a full list of bug fixes, please refer to the release candidate […]












