-
CISA Orders Immediate Patching of Multiple Actively Exploited Critical Vulnerabilities
Federal agencies must secure Citrix NetScaler, Oracle WebLogic, and Gitea instances against active remote code execution and cryptojacking campaigns.
-
WhatsApp Implements Multiple Passkeys and Alphanumeric Two-Step Verification
The messaging platform is expanding phishing-resistant authentication options and upgrading two-step verification to support complex passwords.
-
Attackers exploit miniOrange SAML SSO plugin vulnerabilities in WordPress
A silent patching oversight leaves paid versions of the miniOrange SAML 2.0 Single Sign On plugin vulnerable to authentication bypasses that grant administrative access.