A public exploit for the wp2shell flaw has kicked off a scanning wave against WordPress. Honeypots log tens of thousands of attempts — if you haven’t installed 6.9.5 or 7.0.2 yet, you’re behind.
CVE-2026-42533 has been sitting in Nginx since 2011: a heap overflow in regex map handling crashes worker processes and might enable code execution. Fixed builds are out now.
A record WAIC in Shanghai: 1,100+ exhibitors, 300 world debuts and Huawei’s Atlas 950 SuperPoD with 8,192 Ascend chips — China’s AI stack increasingly skips US parts.
A critical deserialization bug in on-prem SharePoint (CVSS 9.8) came under attack right after Microsoft’s record Patch Tuesday. Stolen machine keys keep intruders in even after patching.
Google has shipped an out-of-band security update for Chrome. At least one of the patched flaws is already being used in attacks — don’t put this one off.
The EU’s cybersecurity rules cover far more organisations than many expect — from hospitals to emergency services. A look at who is affected by NIS2 and KRITIS.
SoftMaker is letting users test-drive the next version of its office suite. Interesting for anyone who wants MS Office compatibility without a forced cloud.