A new critical severity vulnerability can give attackers full control over WHM servers, allowing them to steal data, upload malware, and delete websites.
…
Bluekit centralizes and automates entire phishing campaigns, and is capable of stealing sessions, avoiding detection, and spoofing locations.
…
The security bug is now fixed, but the patient who found it said it was challenging to alert the software company about the issue.

Summary: AI-driven threats are accelerating as security stacks grow louder. Jan Lane argues that leadership clarity, AI integration, workforce awareness and diligence now determine cyber resilience. Rising cybersecurity budgets suggest preparedness, ye…
New report shows Trump, Vance and Rubio are the most deepfaked US politicians.
We hear how 1Password is helping Oracle Red Bull Racing get back to pole position in Formula 1 2026.
Extremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure.
A critical DotNetNuke vulnerability allows attackers to upload malicious SVG files, execute XSS, and gain server control through authenticated user actions.
…
More than 150,000 people allegedly affected, including tens of thousands of professional athletes.
Forcepoint uncovers new phishing campaign using DHL assets, and even found where the passwords are being sent to.