Vulnerabilities, data leaks, GDPR

Latest security news

What website owners need to know right now – researched and explained in plain language.
Researched & explained in plain language
What website owners should know right now
Critical Elementor Pro Flaw: Attackers Can Fully Take Over WordPress Sites
A file upload bug in Elementor Pro up to 4.2.1 allows RCE without login. Version 4.2.2 fixes the flaw – update now!
Pods Plugin: Critical Flaw Enables Admin Takeover, No Login
A critical flaw in the WordPress plugin Pods lets attackers overwrite admin passwords without login. Over 100,000 sites are affected.
miniOrange SAML SSO: Critical Bypass Turns Attackers Into Admins
Two critical auth bypasses in the miniOrange SAML SSO plugin allow forged SAML assertions—up to full WordPress admin access.
Zimbra RCE Actively Exploited: Mail Servers at Risk via SNMP
An actively exploited command injection in Zimbra enables RCE without login. Patch 10.1.20 available - act now to protect your servers.
Critical Forminator Flaw Endangers Over 600,000 WordPress Sites
CVE-2026-15748 allows unauthenticated file upload in Forminator Forms. Updating to 1.56.2 protects against full site takeover.
SafePal Data Leak: Order-Tracking Plugin Hits 39,798 Customers
An authorization flaw in the order-tracking plugin exposed names, contact data and order details. Wallet data stayed safe, per SafePal.
SANDCLOCK: LiteLLM Supply Chain Attack Siphons CI/CD Secrets
Compromised LiteLLM PyPI versions 1.82.7/1.82.8 steal cloud keys and tokens. Over 2,500 organizations affected.
Akira Ransomware Bypasses EDR via Safe Mode After SonicWall VPN Attack
An Akira attacker used a SonicWall VPN without MFA, exfiltrated data, and booted hosts in safe mode to disable EDR and Defender.
VMware vCenter Flaw Actively Exploited: 55 IPs in Germany Hit
China-linked group exploits CVE-2026-59310 in vCenter: backdoors, web shells and Babuk ransomware on ESXi. What you need to do now.
Cl0p Claims Data Theft at Philips, Shell and Around 50 Firms
The extortion group Cl0p lists nearly 50 victims, including Philips and Shell. Flaws in PTC Windchill and FlexPLM are seen as the entry point.
CVE-2026-20349: Cisco Firewall Flaw Actively Exploited for DoS
Cisco confirms active attacks on ASA and FTD: A crafted HTTP request reboots VPN appliances without login. Hotfixes are now available.
Stored XSS in Embed Google Photos album threatens WordPress up to 2.2.1
Contributors can inject JavaScript into posts via shortcode – executed for every visitor, including admins. A fix is still missing.