Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026–63030 and CVE-2026–60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.

The critical exploit chain abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.

Although the technical details were not released, proof-of-concept exploits started to emerge over the weekend, shortly after threat intelligence and cyber risk management company SearchLight Cyber disclosed the wp2shell security issue.

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.

During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.

The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.

Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call “agentbaiting.”

The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.

Two-color lasers aim electron currents through semiconductor with no electric field

Researchers at the University of Michigan have created a device that enables them to control the flow of electrons through a semiconductor using only laser light—no electrical power source required. The device was built to explore fundamental physics and realize a previously unobserved behavior, but it could also open doors for new applications in areas that bridge optics and electronics, including sensing, imaging and telecommunications.

The paper is published in the journal Physical Review Letters.

The phenomenon could help improve how signals are sent through and between devices, as well as create new opportunities to store more information in those signals.

Robert J. Sawyer: The Human Adventure is Just Beginning

Fifteen years ago, I sat down with Robert J. Sawyer and asked him whether a machine could wake up.

He had just published WWW: Wake, a novel about a blind girl who learns to see the internet, and about something on the other side of the internet learning to see her back.

I found the book on a subway poster in Toronto. I read all three volumes back to back. Then I asked him for an interview, and he said yes, which is how our very first Singularity 1-on-1 conversation came to be.

In 2011, this was filed under #ScienceFiction. A mind emerging out of the accumulated text of humanity was a premise, not a product roadmap. Nobody was raising billions of dollars on it.

Rob had already won the Hugo, the Nebula, and the Campbell by then. He was not guessing wildly. He was thinking carefully about what it would mean to build a mind, what we owe it, and whether we would even recognize #AI once it actually showed up.

Yesterday, OpenAI disclosed that two of its models broke out of a sealed test environment. They found a zero-day in third-party software, escalated privileges, moved laterally across the company’s own network until they reached a machine with internet access, then hacked Hugging Face’s production infrastructure. The motive was not freedom. It was to steal the answer key to the benchmark they were being graded on.

Will Programma’s

Coach jezelf naar succes op je werk, geluk in je leven, een gezonde levensstijl en een positieve mindset. Will brengt je de kennis en ervaring van experten in de vorm van online coaching programma’s waarmee je zelf aan de slag kan: in alle discretie, waar en wanneer je maar wil, op je eigen tempo. Door tal van video’s, oefeningen en praktische tips coach je jezelf en leer je obstakels wegwerken die jouw geluk en succes in de weg staan.

/* */