Critical WordPress core vulnerability patched, update to 7.1.2 now

WordPress released version 7.1.2 yesterday, an emergency security update that fixes a critical flaw in core. Every WordPress version from 4.7 through 7.1.1 is affected, which covers the vast majority of sites on the internet. The vulnerability, tracked as CVE-2026-87902 and scored 9.2 out of 10 on the CVSS scale, is in the way WordPress … Continued

Brevo supply chain attack pushed malware to over 100,000 websites

On 14 September, attackers turned the email marketing platform Brevo into a malware distribution channel. For around five and a half hours, more than 100,000 websites that embed Brevo’s JavaScript widgets served malicious code to their visitors, in what is being described as one of the biggest web supply chain attacks of the year. The … Continued

LastPass breach affects 25.6 million users

In recent years, LastPass has become the go-to choice for those seeking a free and mainstream password manager. Unfortunately, the security service has recently disclosed a massive data breach that has left its 25.6 million users concerned. The company has yet to provide further information about the incident, including how many password vaults were compromised, … Continued

Royal Mail Experiencing Severe Disruption Following Cyber Attack

Royal Mail is facing another major disruption as a result of a cyber attack, which has left hundreds of thousands of letters and parcels stuck in limbo. The attack is suspected to have come from a Russian-linked ransomware gang called Lockbit, and it has already caused “severe disruption” to Royal Mail’s international export services, with … Continued

“Dirty Pipe” vulnerability

Linux Kernel 5.8 and later versions are vulnerable to a new exploit called Dirty Pipe. The vulnerability, tracked as CVE-2022-0847, allows a non-privileged user to inject and overwrite data in read-only files, including SUID processes that run as root. The vulnerability was discovered by Max Kellermann after he was tracking down a bug that was … Continued

UK Organisations urged to boost defences

The NCSC (National Cyber Security Centre) has issues new guidance to UK organisations to help protect themselves from cyber attacks that are suspected to have been started by Russia. The attacks in Ukraine have caused power outages and disruption to everyday life, and the NCSC wants UK companies to be prepared in case something similar … Continued