WORDPRESS FLAW EXPOSES PATH TRAVERSAL, RCE RISK
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.
■ MORE FROM THE SECURITY DESK
Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.
GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.
A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.
The ShinyHunters extortion gang claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, stealing sensitive data on employees and job applicants. The group also defaced the FBI's jobs website.