← Back
VulnerabilityThe Hacker News·4 hours ago

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain unauthorized access as any user including administrators. The flaws require no authentication and have been disclosed by Patchstack, with at least one tracked as CVE-2026-61979 carrying a CVSS score of 8.1. WordPress administrators using this plugin should prioritize patching immediately to prevent account takeover attacks.

Read full article at The Hacker News

Related Articles

VulnerabilityMalwarebytes Labs·1 hour ago

Encrypted instructions can fool AI assistants like Grok and Gemini

Researchers have demonstrated that prompt injection attacks can evade AI safety measures by concealing malicious instructions within encrypted text, potentially compromising guardrails in popular AI assistants. This technique highlights a significant vulnerability in current AI security implementations, allowing attackers to manipulate models like Grok and Gemini into executing unintended actions despite their built-in protections.

VulnerabilityInfosecurity Magazine·2 hours ago

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Australian officials are warning TeamCity customers of an active exploitation campaign targeting a critical server vulnerability and urging immediate patching. The alert mirrors a similar warning previously issued by US government authorities, indicating the flaw poses a significant threat across international organizations.

VulnerabilityThe Register·2 hours ago

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

CISA has issued an emergency three-day patching deadline for a critical Oracle vulnerability that was disclosed in January and subsequently exploited in the wild, as evidenced by honeypot activity. The urgency reflects the flaw's severity and active exploitation, requiring U.S. government agencies to prioritize immediate remediation of this high-risk vulnerability.

VulnerabilityHelp Net Security·3 hours ago

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

At least 274 internet-facing Zimbra Collaboration Suite instances have been actively compromised by unknown attackers exploiting CVE-2026-73570, according to the Shadowserver Foundation. The vulnerability is a code injection flaw in ZCS that Synacor patched in version 10.1.20 released on July 20, 2026, leaving unpatched deployments at risk.