π΅οΈ RESEARCH & DEEP DIVES
-
WordPress WPKoi Templates for Elementor plugin through 3.7.2 vulnerable to DOM-based XSS (CVE-2026-85302)
A DOM-based cross-site scripting vulnerability (CVE-2026-85302) was disclosed in the WordPress WPKoi Templates for Elementor plugin affecting all versions through 3.7.2.- Affects WordPress sites using the WPKoi Templates for Elementor plugin, an Elementor addon with 400+ page templates and creative widgets, in all versions from n/a through 3.7.2.
- The flaw is CWE-79 improper input neutralization during web page generation, allowing DOM-based cross-site scripting (XSS).
- CVSS 3.1 score is 6.5 (medium): network vector, low attack complexity, low privileges required, user interaction required, scope changed.
- The vulnerability was assigned by Patchstack and reported by Abdullah Kareem 'cyberkareem' via the Patchstack Bug Bounty Program; it was published 2026-09-03.
- A fix is available in plugin version 3.7.3, per the WordPress.org plugin directory.
π Source: patchstack.com Β· π Coverage: radar.offseq.com Β· π via CVE ThreatInt
-
CrowdStrike Launches SafeMind AI Initiative With Models Trained for Cybersecurity
CrowdStrike has launched SafeMind, an AI initiative built on models purpose-trained for cybersecurity.- Applies to CrowdStrike customers and security teams following announcements at the Fal.Con 2026 event.
- The SafeMind initiative centers on a family of purpose-built AI models and harnesses designed specifically for cybersecurity.
- At its core is a pair of models, each trained to launch and to defend against cyberattacks.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
-
Reddit thread asks for opinions on TryHackMe's new AI Security certification
A Reddit user asked the cybersecurity community for opinions on TryHackMe's new AI Security certification.- Posted in r/cybersecurity by user SonicDasherX asking whether anyone has taken TryHackMe's newly launched AI Security certification
- The poster asked whether any companies already require or request the certification in job applications
- The thread had not drawn notable answers in the clustered feed material, so no assessments of the certification's value were available
π Coverage: reddit.com Β· π via r/cybersecurity
π΅οΈ RESEARCH & DEEP DIVES
-
HPE patches critical ArubaOS-CX remote code execution flaw β BleepingComputer
-
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root β The Hacker News
-
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory β The Hacker News
-
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data β The Hacker News
-
VU#889462: Casdoor authentication server is vulnerable to authorization bypass β CERT/CC Vulnerability Notes
-
ASCII smuggling crosses over from AI prompt injection to phishing evasion β Microsoft Security Blog
-
itsourcecode Online Medicine Delivery System Customer Controller controller.p... β CVE ThreatInt
-
WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) ... β CVE ThreatInt
-
WordPress SureForms plugin through 2.12.5 - Insecure Direct Object References (IDO... β CVE ThreatInt
-
WordPress KP Agent Ready plugin before 1.2.08 - Sensitive Data Exposure vulnerabil... β CVE ThreatInt
-
OpenList: Authenticated arbitrary file write via Content-Disposition path tra... β CVE ThreatInt
-
WordPress MountDev AI MCP Connector for WordPress plugin through 1.6.5 - Broken Ac... β CVE ThreatInt
-
WordPress Booking and Rental Manager plugin through 2.7.7 - Cross Site Scripting (... β CVE ThreatInt
-
WordPress Quick Event Manager plugin through 9.17 - Cross Site Scripting (XSS) vul... β CVE ThreatInt
-
WordPress WC Ukraine Shipping plugin through 1.22.3 - Insecure Direct Object Refer... β CVE ThreatInt
-
WordPress JobSearch plugin through 3.2.0 - PHP Object Injection vulnerabilityUnaut... β CVE ThreatInt
-
WordPress Bricksforge plugin through 3.1.8.8 - Privilege Escalation vulnerabilityS... β CVE ThreatInt
-
WordPress GeoDirectory plugin through 2.8.174 - SQL Injection vulnerabilityUnauthe... β CVE ThreatInt
-
WordPress BP Better Messages plugin through 2.15.27 - Cross Site Scripting (XSS) v... β CVE ThreatInt
-
WordPress Agentimus β AI SEO, llms.txt & MCP for AI Agents plugin through 1.51.0 -... β CVE ThreatInt
-
WordPress Migrate Guru β Site Migration & Cloning plugin through 6.65 - Denial of ... β CVE ThreatInt
-
WordPress Really Simple SSL plugin through 9.8.0 - 2FA Bypass vulnerabilityUnauthe... β CVE ThreatInt
-
Signature Optional - Analysis of CVE-2026-28323 β Bishop Fox Blog
-
LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access β Cyber Security News
-
BTS #81 β Infratrust Pulse, AIβs Role in Security β securityboulevard.com (discovered)
-
What Are the Main Types of AI Gateways? LLM, MCP, and Agent Gateways Explained β securityboulevard.com (discovered)
-
The Harness Advantage in Autonomous Red Teaming: Why Frontier LLMs Alone Fail Offensive Security and How RidgeGen Solves the Alignment Dilemma β securityboulevard.com (discovered)
-
The Honor System Is Ending: Four Places Trust Went Cryptographic β securityboulevard.com (discovered)
-
A Stop AI Rogue Act has been introduced. β @metacurity@infosec.exchange
-
I'm really tired of all the Hugging Face post-mortems, but this is worth a listen. β @metacurity@infosec.exchange
-
βNot perfectly alignedβ with human values: Anthropic admits security failures behind AI hacking incidents | US owner of Claude chatbot previously said its models had hacked three organisations during testing β r/cybersecurity
-
Designing a Fail-Closed & Bare-Metal Zeroization Engine: Architectural Challenges β r/cybersecurity
-
What do you guys use for quick cybersecurity news? β r/cybersecurity
-
Splunk Dashboards and Alerte β r/cybersecurity