#Web Security
13 stories taggedWeb Security.

Claude Opus 4.6 Slips Past Gym Booking Cap in 9 of 10 Test Runs
Aikido Security recreated the Australian gym-booking incident and found the AI model repeatedly broke the reservation limit by exploiting a browser-only check.

WordPress Login Flaw Lets Attackers Slip Code Into Every Site Running It
A newly disclosed bug on the WordPress sign-in page affects every version of the software and, in the wrong conditions, can hand attackers full control of the server.

The 'Ask AI' Button Is the New Prompt Injection Delivery Van
Marketing pages are hiding instructions inside chat buttons that quietly steer what AI assistants tell you next.

Your Email's Design Layer Can Steal Your Password. No Suspicious Attachment Required.
Security researcher Gareth Heyes found that CSS, the code responsible for how emails look on screen, can be turned into a data-theft tool inside popular webmail services. No malicious files. No links to click.

A Rails Bug Lets Strangers Read Your Server's Secrets Through a Photo Upload
CVE-2026-66066 in Active Storage scores a 9.5 out of 10 for severity, and no login is required to exploit it.

Anyone Can Now Attack Unpatched vBulletin Forums Thanks to Public Exploit Code
Working exploit code for a critical vBulletin flaw is out in the open, and it lets a stranger run commands on the server without logging in.

WP2Shell: Two WordPress Flaws Let Attackers Take Over Websites Without Logging In
Criminals are actively exploiting a pair of newly discovered security holes in WordPress to seize full control of websites. Tens of millions of sites were at risk, and patching may already be too late for some.

A Flaw in WordPress's Core Code Lets Criminals Take Over Websites Without Logging In
A newly discovered vulnerability in WordPress versions 6.9 and 7.0 lets attackers run their own commands on any affected site with no password required. Patches are out now.

WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk
A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code
A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

CISA flags active attacks on two Joomla add-ons that let hackers take over websites
Old flaws in the iCagenda and Balbooa Forms extensions are being used to plant malicious files on Joomla sites, and the U.S. cyber agency has given federal bodies three weeks to patch.

Hackers Are Breaking Into Websites Through Two Popular Joomla Add-Ons
Two widely used plugins for the Joomla website-building platform have critical security flaws that let criminals take full control of a site without needing a password. Patches exist, but attacks started before most site owners knew there was a problem.

Privilege Escalation Attacks Hit Kirki and Burst Statistics WordPress Plugins
Threat actors are actively exploiting flaws in two widely-used WordPress plugins to grab admin access and seize site control.