Posts by Editorial Team
miniOrange SAML SSO Bypass Vulnerability
A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…
Read MoreGitLab GraphQL code injection vulnerability
A GitLab GraphQL code injection vulnerability is now under active exploitation, reproduced and attacked within minutes of GitLab’s August 17, 2026 disclosure of CVE-2026-19478. The unauthenticated flaw (CVSS 9.4) lets an attacker delete public projects, forge fake fix records, or lock out maintainers on any unpatched self-managed GitLab instance. GitLab.com and GitLab Dedicated were already…
Read MoreIdentity Theft in Germany: What SMEs Need to Know
Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…
Read MoreZimbra Command Injection Vulnerability Actively Exploited
A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…
Read MoreWindows Defender Zero-Day Vulnerability Has No Patch
A Windows Defender zero-day vulnerability disclosed on August 12, 2026 lets a low-privileged local attacker bypass Microsoft’s own patch for an earlier Defender flaw and escalate straight to SYSTEM. Tracked as CVE-2026-69414 and nicknamed ShieldBreak, the flaw still has no fix ten days after Microsoft assigned the CVE. Any Windows endpoint running default Defender is…
Read More
