*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability, which was classified as problematic, was found in Vitepos Plugin up to 3.5.x on WordPress. Affected is an unknown function. Executing a manipulation can lead to sql injection. This vulnerability appears…
A vulnerability, which was classified as critical, has been found in Vitepos Plugin up to 3.5.9 on WordPress. This impacts an unknown function. Performing a manipulation results in improper privilege management. This vu…
A vulnerability classified as critical was found in Booking for Appointments and Events Calendar Plugin up to 9.6 on WordPress. This affects an unknown function. Such manipulation leads to authorization bypass. This vul…
A vulnerability classified as problematic has been found in HT Contact Form Plugin up to 2.9.2 on WordPress. The impacted element is an unknown function. This manipulation causes information disclosure. This vulnerabili…
A vulnerability described as critical has been identified in Arvow AI SEO Writer Plugin up to 1.5.3 on WordPress. The affected element is an unknown function of the component REST Endpoint. The manipulation results in i…
A vulnerability marked as critical has been reported in AutoNetTV Relay Plugin up to 3.0.13 on WordPress. Impacted is an unknown function. The manipulation leads to improper authentication. This vulnerability is listed …
A vulnerability labeled as critical has been found in WooCommerce Customer Reviews for WooCommerce Plugin up to 5.115.x on WordPress. This issue affects some unknown processing. Executing a manipulation can lead to miss…
A vulnerability identified as critical has been detected in Eventin Plugin up to 4.1.19 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in path traversal. This vulnerability is i…
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident o…
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding…
Anthropic’s Claude Opus 5 has recorded the lowest indirect prompt injection attack success rate in Gray Swan’s latest benchmark, according to results provided in its system card. The model reduced an attacker’s chance o…
The vulnerabilities affected software used by eight of Belgium’s ten largest banks and over 60 government agencies. The post Critical Flaws Discovered in Belgian eID Software Used by 2 Million People appeared first on S…
A vulnerability categorized as critical has been discovered in Libexpat up to 2.8.2. This affects the function *_toUtf16 of the component Unicode Handler. Such manipulation leads to out-of-bounds read. This vulnerabilit…
Windows 11’s default Weather app, a fixture on the taskbar for millions of users, is under fire after independent testing revealed it consumes more than 1.2GB of RAM just to display a simple forecast and map. The findin…
A vulnerability was found in Red Hat Enterprise Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the component ASF demuxer. This manipulation causes integer overflow. The ide…
A vulnerability was found in Red Hat Enterprise Linux 7/8/9/10. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component ADPCM Decoder. The manipulation results …
An Australian man’s AI assistant has become the center of what is being described as the country’s first known autonomous AI cyberattack, after it exploited a security flaw in a gym’s booking system to secure him a clas…
In other news: Metabase zero-day used in data theft attacks; Russian hackers disrupted a second power plant in Poland; two US law firms pay mega ransoms.
A vulnerability was found in NLTK up to 3.9.4. It has been classified as problematic. Affected is the function nltk.pathsec.validate_network_url. The manipulation leads to server-side request forgery. This vulnerability…