Identity and Access Your phone asks you to approve a sign-in you did not start. What should you do?
One unexpected MFA prompt could be a mistake; a stream of them may be an attempt to wear you down. The right response is simple and non-technical.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Identity and Access One unexpected MFA prompt could be a mistake; a stream of them may be an attempt to wear you down. The right response is simple and non-technical.
Human Security The offer arrives on WhatsApp, the tasks are effortless and the balance keeps growing. Learn how a task scam turns apparent earnings into a real loss.
Human Security A message from an apparent child soon turns into a request for money. Use a simple family verification routine that still works under pressure.
Human Security A call from a bank or support desk ends with a request for remote access. Learn when to end the call and what to do after sharing your screen.
Human Security A criminal may build closeness for weeks before revealing an apparent opportunity. Learn the manipulation signs and a response that does not start with shame.
Human Security School messages, parent groups, urgent payments and new login links. A simple family plan that improves safety without turning home into an IT department.
Vulnerabilities and CVEs Two BEAM atom-table exhaustion paths, denied-field disclosure, missing constraints and URL bugs expose risks at the Elixir–TypeScript boundary.
Cloud, Infrastructure and DevSecOps OS command injection in Plesk for Linux lets a customer or reseller with shell access become root. Fixes are in 18.0.79.9 and 18.0.80.5.
Supply Chain Security A scoped path-traversal package name let pnpm overwrite arbitrary files even with --ignore-scripts. Fixes are available in 10.34.5 and 11.11.0.
Vulnerabilities and CVEs WPLP Cookie Consent for WordPress allowed authorization bypass and arbitrary file upload. Versions through 4.4.1 need an urgent update to 4.4.2.
AI Security Six ash_ai vulnerabilities show why agent security spans the entire runtime: prompt rendering, record filters, error handling, MCP and tool-loop progress.
AI Security Missing workspace containment in Agent Mode file tools let model-supplied paths reach files available to the Theia backend. Version 1.75.0 fixes it.
Vulnerabilities and CVEs A weak 32-bit connect token let a guest trigger plugin installation and activation from a chosen URL. ProfilePress 4.17.2 contains the fix.
Vulnerabilities and CVEs Missing authorization in send_link() and improper token validation in activate() can expose an unconfirmed WordPress account, including an administrator account.
Identity and Access An Erlang OIDC library accepted a JWE carrying attacker-authored claims without a nested signature. Here is why encryption is not sender authentication.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.