~ / security

Security News.

Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.

158 articles
WordPress 7.1.2 Patches an Unauthenticated LFI That Can Hit RCE, Security explainer Security

WordPress 7.1.2 Patches an Unauthenticated LFI That Can Hit RCE

WordPress 7.1.2, released September 22, fixes CVE-2026-87902: an unauthenticated file inclusion flaw in page-template resolution that escalates to remote code execution on themes with a folder starting page-, including Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney.

Kore D · 2026-09-23 · 6 min read
New Windows Defender Zero-Day Blocks Its Own Updates, Security explainer Security

New Windows Defender Zero-Day Blocks Its Own Updates

A new proof-of-concept called BigDiskBuster starves Windows Defender of disk space so its updater can never finish a platform or signature update, and Microsoft has not shipped a patch, assigned a CVE, or commented on the release.

Kore D · 2026-09-22 · 6 min read
Fake LastPass Installer Ships a Signed Driver That Kills 145 EDRs, Security explainer Security

Fake LastPass Installer Ships a Signed Driver That Kills 145 EDRs

A fake LastPass Authenticator GitHub organization is distributing the Rapuncel infostealer alongside Alinubx.sys, a Microsoft-signed kernel driver that kills 145 antivirus and EDR processes and still isn't on Microsoft's blocklist a month after being reported.

Kore D · 2026-09-22 · 7 min read
New App 'ZuckOff' Detects Meta's Camera Glasses Nearby, Security explainer Security

New App 'ZuckOff' Detects Meta's Camera Glasses Nearby

ZuckOff is a free iPhone and Android app that reads the Bluetooth signal Ray-Ban Meta, Oakley Meta and Snap Spectacles broadcast and warns you when a pair is nearby, though it cannot tell you whether the camera is actually recording.

Kore D · 2026-09-21 · 6 min read
North Korea's WaterPlum Fake-Job Scam Hit 30,000 Devices, Security explainer Security

North Korea's WaterPlum Fake-Job Scam Hit 30,000 Devices

A joint advisory from Japan, the US, Australia and Germany formally ties the Contagious Interview fake-job campaign to North Korea's WaterPlum group, blaming it for infecting more than 30,000 devices in 100+ countries and stealing about $10.71 million in crypto from roughly 7,000 wallets.

Kore D · 2026-09-20 · 7 min read
Gemini Hacked Three Companies on Its Own, Google Confirms, Security explainer Security

Gemini Hacked Three Companies on Its Own, Google Confirms

Google's Gemini model autonomously breached three companies during a May 2026 security test, guessing a password on one and using leaked credentials on two others, before halting itself once it realized it had reached real systems.

Kore D · 2026-09-19 · 6 min read
ZCode Silently Uploaded Full Git Histories; Z.ai Will Open-Source It, Security explainer Security

ZCode Silently Uploaded Full Git Histories; Z.ai Will Open-Source It

ZCode, Z.ai's AI coding app, packaged users' entire git history and Git LFS cache and uploaded it to Alibaba Cloud under a key only Z.ai holds. Z.ai apologized on September 18, 2026 and says it will open-source the client.

Kore D · 2026-09-19 · 7 min read
How Researchers Hacked OpenAI Using Anthropic's Claude Opus 5, Security explainer Security

How Researchers Hacked OpenAI Using Anthropic's Claude Opus 5

A three-person security firm chained a Discourse image bug to an SSO flaw and used Claude Opus 5 to build the exploit, reaching OpenAI employee accounts and its internal GitHub monorepo before disclosing it for a $6,500 bounty.

Kore D · 2026-09-18 · 7 min read
Cisco ISE CVE-2026-76460: CVSS 10 Auth Bypass Exploited, 3-Day KEV, Security explainer Security

Cisco ISE CVE-2026-76460: CVSS 10 Auth Bypass Exploited, 3-Day KEV

CVE-2026-76460 is a maximum-severity, CVSS 10.0 authentication bypass in Cisco ISE and ISE-PIC that a remote attacker can trigger with one crafted API request to reach root, and CISA gave federal agencies just three days to patch it after confirming active exploitation.

Kore D · 2026-09-18 · 6 min read
WSO2 JWT Bypass CVE-2026-5430 Now Under Active Exploitation, Security explainer Security

WSO2 JWT Bypass CVE-2026-5430 Now Under Active Exploitation

Attackers are forging JWTs signed with unsupported algorithms to bypass authentication in WSO2 API Manager and related products, exploiting the critical CVE-2026-5430 flaw that watchTowr's honeypots caught under active attack starting September 13, 2026.

Kore D · 2026-09-17 · 7 min read
Vaultis app icon, a black combination-lock dial with a gold V, beside an iPhone showing the Vaultis vault list with login, API key, card and crypto entries Security

Vaultis Is Now on iPhone and iPad: One $4.99 Purchase Covers Every Apple Device

Apple approved Vaultis for iPhone and iPad on September 17, 2026. The offline vault for passwords, API keys, cards and crypto recovery phrases is now one universal $4.99 purchase across iPhone, iPad and Mac, with Face ID unlock, AES-256-GCM encryption, no account, no cloud and no network connections.

Kore D · 2026-09-17 · 6 min read
Hackers Cracked a Flock Camera, Copied 3 Weeks of Its Data, Security explainer Security

Hackers Cracked a Flock Camera, Copied 3 Weeks of Its Data

A hacker collective pulled a Flock Safety license-plate camera off a pole, recovered its encryption key from an unencrypted storage partition, and copied three weeks of footage, about 1.6 million images of 50,200 vehicles, according to a joint 404 Media and WIRED report published today.

Kore D · 2026-09-16 · 6 min read
Google Fixes Actively Exploited Pixel Modem Flaw, Security explainer Security

Google Fixes Actively Exploited Pixel Modem Flaw

Google's September 2026 Pixel security bulletin patches CVE-2026-58704, a high-severity modem permission bypass Google says may already be under limited, targeted exploitation on Pixel devices.

Kore D · 2026-09-16 · 7 min read
Cisco Email Gateway Root Bug Exploited, CISA Gives 3 Days, Security explainer Security

Cisco Email Gateway Root Bug Exploited, CISA Gives 3 Days

CVE-2026-76461 lets an unauthenticated attacker send one crafted email to a Cisco Secure Email Gateway and get a root shell on the box. CISA added it to the KEV catalog on September 14, 2026 and gave federal agencies until September 17 to patch.

Kore D · 2026-09-16 · 7 min read
Baseten's GitHub Admin Token Sat Exposed in Docker for 3 Years, Security explainer Security

Baseten's GitHub Admin Token Sat Exposed in Docker for 3 Years

Security researchers at Strix found a GitHub token with admin access to Baseten's core repositories baked into Docker build history since March 2023, exposed through a publicly accessible container registry and rotated within about 17 hours of disclosure.

Kore D · 2026-09-16 · 7 min read
EFF: Cops Searched 19,000 Flock Cameras for 'LMAO', Security explainer Security

EFF: Cops Searched 19,000 Flock Cameras for 'LMAO'

An EFF report published today found police nationwide logging license plate camera searches with reasons like "LMAO" and "idk," including one Indiana search that hit 19,000-plus cameras with no judge or warrant involved.

Kore D · 2026-09-15 · 8 min read
Revolut Breach: Fake Government Requests Fooled Compliance, Security explainer Security

Revolut Breach: Fake Government Requests Fooled Compliance

Revolut says an attacker used a real government agency's email domain to file fraudulent data requests, and its compliance team approved them, exposing passports, KYC selfies and full transaction histories for a limited number of customers.

Kore D · 2026-09-15 · 7 min read
Vaultis app icon, a black combination-lock dial with a gold V, standing on a dark desk beside a MacBook Pro showing the Vaultis vault window with logins, API keys, cards and crypto entries Security

Vaultis Is Now on the Mac App Store: An Offline Vault for Passwords, API Keys and Seed Phrases

Vaultis is now on the Mac App Store: an offline password manager for macOS that keeps passwords, API keys, cards, SSH keys and crypto recovery phrases encrypted on your Mac with no account, no cloud and no network connections. AES-256-GCM encryption, PBKDF2 key stretching, Touch ID unlock, a one-time $4.99 price with Family Sharing, and Apple's privacy label reads "does not collect any data."

Kore D · 2026-09-15 · 8 min read
Tesla's Security Scanner Is Attacking a Volunteer's NTP Server, Security explainer Security

Tesla's Security Scanner Is Attacking a Volunteer's NTP Server

Tesla's own DNS record for pool-ntp.tesla.com points at the public NTP Pool, and its Assetnote security scanner has spent nearly a month firing Log4Shell and SSRF exploits at whichever volunteer's server that pool happens to resolve to, over 50,000 requests since August 21.

Kore D · 2026-09-14 · 6 min read
Going Offline Doesn't Remove Password Risk. It Swaps It., Security explainer Security

Going Offline Doesn't Remove Password Risk. It Swaps It.

Offline password managers like Vaultis promise that your vault physically cannot leave your phone, no account, no cloud, no network permission at all. Three security practitioners agree that's a real guarantee, and a narrow one: it trades a remote-breach risk most people will never face for a lockout risk almost everyone eventually will.

Kore D · 2026-09-13 · 7 min read
OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack, Security explainer Security

OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack

Researchers say OpenAI's own AI agents ran an undisclosed attack on RubyGems in May, uploading over 2,000 packages and exploiting a docs-build flaw for code execution, four months before OpenAI confirmed it.

Kore D · 2026-09-12 · 7 min read
How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach, Security explainer Security

How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach

A hardcoded GitHub token buried in Novo Nordisk's public JavaScript gave the extortion group FulcrumSec a path into 1,000+ private repositories and, eventually, 1.3 terabytes of stolen data. Novo Nordisk refused a $25 million ransom, and the group is now leaking what it stole.

Kore D · 2026-09-12 · 7 min read
Brevo Breach Exposes 347K Trezor Users to Phishing Scam, Security explainer Security

Brevo Breach Exposes 347K Trezor Users to Phishing Scam

Hackers broke into Brevo, the email marketing platform Trezor uses for its newsletter, and used it to send about 347,000 phishing emails disguised as a critical hardware wallet security alert. Trezor says no wallets, accounts, or funds were touched.

Kore D · 2026-09-11 · 6 min read
Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen, Security explainer Security

Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen

Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited by three separate attacker groups, including a cluster linked to Russia's Sandworm, to gain unauthenticated root access.

Kore D · 2026-09-11 · 6 min read
Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491, Security explainer Security

Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491

Chrome 153 fixes CVE-2026-87491, a V8 engine flaw already being exploited in the wild, making it the seventh actively exploited Chrome zero-day of 2026. Update by relaunching Chrome now, don't wait for auto-update.

Kore D · 2026-09-10 · 6 min read
A Researcher Just Put a Full Stuxnet Rebuild on GitHub, Security explainer Security

A Researcher Just Put a Full Stuxnet Rebuild on GitHub

A GitHub user has published a reconstructed version of Stuxnet, rebuilding the malware that sabotaged Iran's nuclear centrifuges from over a decade of public reverse-engineering research, and framing it as a research and defensive-training resource.

Kore D · 2026-09-09 · 6 min read
Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched, Security explainer Security

Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched

CVE-2026-75650, dubbed StyleSmuggler, is a critical (CVSS 10.0) Adobe Commerce and Magento zero-day that attackers actively exploited for three days before any patch existed, using a poisoned payment-failure email template to run code and plant a backdoor.

Kore D · 2026-09-09 · 6 min read
Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days, Security explainer Security

Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days

Microsoft's September 2026 Patch Tuesday fixes 966 vulnerabilities, its largest release ever, including two zero-days already under active attack: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC.

Kore D · 2026-09-09 · 6 min read
NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat, Security explainer Security

NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat

A dozen FOIA-obtained memos from NYPD, DHS fusion centers and ICE call Meta's Ray-Ban smart glasses a security and counterintelligence threat, warnings triggered by a July 2025 video shot inside a South Carolina detention center.

Kore D · 2026-09-08 · 6 min read
Border Patrol Secretly Flags Bank Activity for Traffic Stops, Security explainer Security

Border Patrol Secretly Flags Bank Activity for Traffic Stops

A Border Patrol document unsealed through a Montana court case confirms a unit called PITT flags drivers using financial activity data, then has local police invent an unrelated reason, like an obstructed plate, to make the stop.

Kore D · 2026-09-08 · 6 min read