CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
The European password manager Passwork is developed by Russian founders, shares identical source code with a Russian variant certified by Russian security authorities, and supplies sanctioned defense contractors.
ACR Stealer infects enterprise customers through fake error messages with manipulated commands and steals browser data, credentials, and cloud content.
EY customers exposed their tax documents between March and April 2026 through a compromised support ticketing access point, with the exact number of affected customers remaining unclear.
Fraunhofer is developing person-centric voice profiles to detect audio deepfakes as general detection methods can no longer keep pace with rising synthesis quality.
AI-accelerated vulnerability discovery reveals decades of accumulated technical security debt at a pace that could overwhelm SOC teams through cognitive overload.
Claude Mythos identifies critical security gaps at scale – Anthropic limits access through Project Glasswing and offers a guardrailed parallel model called Claude Fable 5.