The WordPress Update Was Backdoored, Then Its Replacement Was Compromised Too

Installing the replacement was not enough: the developer says a second intrusion compromised it too. Site owners need a recovery decision, not another green update badge.

Installing the replacement was not enough: the developer says a second intrusion compromised it too. Site owners need a recovery decision, not another green update badge.
Google's September bulletin flags possible targeted exploitation of a Pixel modem flaw, now also listed in CISA's exploited-vulnerability catalogue. The useful check is the installed patch level.

The backup integration behind a hosting control panel has an exploited Linux privilege-escalation flaw. An attacker needs a local foothold first, but that is not where the risk ends.

The browser can load the malicious extension as though you approved it. Elastic's KREMLIN investigation shows why a familiar banking document can become an endpoint and session-security problem.

The platform deciding who may enter your network has an exploited login bypass. Patching Cisco ISE closes the flaw, but deciding whether a node can still be trusted takes a separate investigation.

Ace & Tate has confirmed that customer contact, order and delivery details were copied from logistics partner CEVA. The fields can make delivery scams more convincing even though payment data and passwords were not involved.

InjectEave researchers recovered headphone audio through induced electromagnetic leakage from as far as 30 metres in a controlled test. What the experiment does and does not prove.

Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.

Japan's Digital Agency detected mass file access in June, identified a VPN-vulnerability intrusion in July and disclosed in September that about 246,000 records may have leaked.

Four PIMBoards flaws have a vendor fix, but old project files, backups and passwords still need separate handling after the software update.