Software

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity […]

Hackers target WordPress sites in miniOrange auth bypass attacks Read More »

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. The flaw is tracked as CVE-2026-75501 and is described as a missing authentication issue that affects devices running EXOS/6.6.47 firmware. Security

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices Read More »

Windows update that breaks some multiplayer games linked to our desire for gaming PCs that light up all the colors of the rainbow

Last week, we covered the very strange occurrence of a bug in the latest Windows update. Yes, a bug in a Windows update, say it isn’t so. Unfortunately, this one does incur our wrath of gamers more than most because it leads to some games becoming unresponsive. Games like Arc Raiders, Marvel Tōkon: Fighting Souls,

Windows update that breaks some multiplayer games linked to our desire for gaming PCs that light up all the colors of the rainbow Read More »

Twitch hit with class-action lawsuit over Amazon AI training: ‘Twitch sent no email, displayed no pop-up notification, and made no announcement’

In yet another unpleasant move in our AI hellscape, Amazon was caught training its generative AI using Twitch stream content earlier this month—a particularly brazen strategy, especially given Twitch’s chief product officer admitted that the data collection was opt-out because “nobody would opt in.” Hmm, I wonder why! Anyway, despite attempts to insist that Twitch

Twitch hit with class-action lawsuit over Amazon AI training: ‘Twitch sent no email, displayed no pop-up notification, and made no announcement’ Read More »

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The Zimbra security team patched the security flaw (tracked as CVE-2026-73570) in version 10.1.20, released on July 20. Successful exploitation allows unauthenticated attackers to gain remote code execution by

CISA orders urgent patching of actively exploited Zimbra flaw Read More »

Chrome’s new rules ruined ad blockers. Here are 4 things that still work

Affiliate links on Android Authority may earn us a commission. Learn more. Unfortunately, this also made it harder to install extensions like the highly popular uBlock Origin. While workarounds still existed by using Chrome flags, that’s no longer the case. It is now virtually impossible to get MV2 extensions to work in Chrome. So, what

Chrome’s new rules ruined ad blockers. Here are 4 things that still work Read More »

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. The attacker impersonates the target company’s IT help desk, a tactic Microsoft highlighted earlier this year as increasingly common in multi-stage attacks. Expel’s security researcher Marcus Hutchins explains that the attacks direct

New SynkLoader malware pushed in Microsoft Teams phishing campaign Read More »

Named Pipes Under Attack: Securing Windows Interprocess Communication

Written by: Farid Mustafayev, Cybersecurity Expert at ThreatLocker Named pipes are a common choice for communication between applications running on the same Windows computer. They are fast, supported directly by the operating system, and work well for communication between Windows services, desktop applications, tray processes, command-line utilities, and background agents. A typical design may include

Named Pipes Under Attack: Securing Windows Interprocess Communication Read More »