CVE-2026-4020 Exploited in Gravity SMTP WordPress Plugin
Hackers are exploiting a medium-severity info disclosure bug in the Gravity SMTP WordPress plugin, affecting 100,000 sites and exposing sensitive information like API keys and credentials.
A 26-year-old Illinois man was sentenced to 76 months in prison for hacking into over 750 women's Snapchat accounts to steal nude photos.
Hackers are exploiting a medium-severity info disclosure bug in the Gravity SMTP WordPress plugin, affecting 100,000 sites and exposing sensitive information like API keys and credentials.
A new BootROM exploit called Usbliter8 affects millions of iPhones, allowing attackers to bypass Apple's SecureROM and execute arbitrary code with full system privileges.
Authorities disrupted the SocGholish botnet, a malware framework used by Evil Corp and other cybercrime groups to steal data and break into networks, seizing infrastructure and remediating nearly 15,000 infected sites.
A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio allows attackers to execute arbitrary commands on a host system by visiting a malicious webpage.
Microsoft attributes a recent Mastra AI supply chain attack to North Korean hacking group Sapphire Sleet, compromising over 140 npm packages.
Threat actors offer searchable underground services for stolen credentials, allowing buyers to request specific company or platform credentials.
A 21-year-old New York man faces cyberstalking charges for sharing AI-generated nude images and fabricated racist messages to harass a Georgia college student.
The latest ShinyHunters breaches highlight the growing risk of identity-based attacks, where attackers target identities, authentication workflows, and trusted access paths to gain unauthorized access to sensitive data.
Klue has confirmed a security incident where threat actors stole OAuth tokens to access customers' Salesforce environments, with the Icarus hackers claiming responsibility for the attack.