CVE-2026-32475: Elementor Pro Bug Exposes WordPress Sites
A critical vulnerability in Elementor Pro, identified as CVE-2026-32475, exposes WordPress sites to remote code execution attacks, affecting versions before 4.2.2.
Attackers exploit identity verification processes, particularly during onboarding and account recovery, to gain unauthorized access to corporate systems.
A critical vulnerability in Elementor Pro, identified as CVE-2026-32475, exposes WordPress sites to remote code execution attacks, affecting versions before 4.2.2.
The Combating Organized Retail Crime Act has bipartisan support, but critics warn it could create a 'very large and very dangerous' surveillance network.
China's 'SilkParasite' espionage operation uses AI-assisted malware to target Central Asia, with five previously undocumented strains of malware discovered.
Citrix warns of two high-severity vulnerabilities in NetScaler Gateway and ADC, CVE-2026-19490 and CVE-2026-19489, which can be exploited for authentication bypass and denial-of-service attacks.
Hackers compromised the maintainer account behind the widely used Rust crate arrayref, introducing malware that executes on developers' systems during compilation, affecting over 53 million downloads.
Kyle William Spitze, a leader of the 764 group, was sentenced to 77 years in prison for producing and distributing child sexual abuse material and animal crush videos.
Clop, a notorious cybercrime group, has exploited a critical zero-day vulnerability in PTC's Windchill and FlexPLM software, stealing data from dozens of organizations, including major publicly traded companies.
A new AI-assisted tool, Argo, helps secure satellite communication systems against emerging adversary attacks, following a 2022 Russian hacking incident that disabled thousands of satellite modems.
A cyberattack on Latvia's Road Traffic Safety Directorate exposed data on 1.2 million people, prompting calls for senior officials to resign.