← All issues
cybersecurityCyberBubblevulnerabilities

Perfect 10: Oracle's Max-Severity Bug Is Being Exploited Right Now

🌐  World Intel
Global: 58 Arrested in International Cybercrime Sweep

Law enforcement from 22 countries worked together to identify 263 suspects and arrest 58 people tied to cybercrime networks run by African crime groups. The operation shows that cross-border police coordination is getting faster and more effective. If you've ever wondered whether cybercriminals face real consequences — this week's answer is yes.

↗ BleepingComputer
United States: TikTok Pays $400M to Settle Children's Privacy Violations

The U.S. Department of Justice announced a $400 million settlement with TikTok and its parent company ByteDance over violations of COPPA, the federal law protecting children's online privacy. The government alleged TikTok collected personal data from kids without proper parental consent. It's the largest children's privacy settlement in U.S. history — and a signal that regulators are watching platforms that attract young users very closely.

↗ BleepingComputer
South Korea: Startup Platform Breach Exposes Encryption Key Blunder

A breach at a South Korean government-backed startup platform exposed encrypted personal data — but here's the painful part: the encryption key that unlocks that data was accidentally included right alongside it in the same API. That's like locking your front door and leaving the key taped to the doorknob. Encryption only protects you if the keys are stored separately from the data they protect.

↗ BleepingComputer
⚔️  Active Attacks
WordPress Sites Under Fire: Hackers Exploiting miniOrange Login Plugin Flaws

Attackers are actively trying to break into WordPress websites using two critical security holes in a popular login plugin called miniOrange SAML 2.0 Single Sign On. The bugs let an attacker bypass the login process entirely and sign in as any user — including the site administrator — without knowing any password. One flaw scores a near-perfect 9.8 out of 10 in severity. The root cause is embarrassingly basic: the plugin's code was treating an error response from a security check the same as a "success" response, essentially waving attackers straight through the front door.

🛡 What to do: If you run a WordPress site using the miniOrange SAML 2.0 Single Sign On plugin, update it to version 17.0.6 or later immediately. Log in to your WordPress dashboard, go to Plugins, and check for available updates.
Microsoft Teams Targeted by SynkLoader Malware Phishing Campaign

A new malware called SynkLoader is spreading through fake Microsoft Teams messages. Attackers send convincing phishing messages inside Teams chats to lure employees into downloading and running the malware. Once installed, SynkLoader can open the door to deeper attacks on a company's network. This is a reminder that phishing doesn't only happen in email anymore — it shows up in the workplace chat tools you use every day.

🛡 What to do: Be skeptical of unexpected file downloads or links sent via Teams, even from people who appear to be colleagues. If something feels off, verify with the sender through a different channel like a phone call before clicking anything.
🔓  New Vulnerabilities
CVE-2026-21962 Oracle WebLogic & HTTP Server CRITICAL 10.0

This is as bad as it gets — a perfect 10 severity score. An attacker anywhere on the internet can access, modify, or delete sensitive data stored on Oracle's widely used WebLogic Server without needing a password or account of any kind. CISA has confirmed this flaw is already being actively exploited in the wild, meaning real attackers are using it right now. Oracle has released patches, but many organizations haven't applied them yet.

Status: Patch available — apply Oracle's fix immediately. CISA has ordered U.S. government agencies to patch within days.

CVE-2026-15981 miniOrange SAML 2.0 WordPress Plugin CRITICAL 9.8

This flaw lets attackers skip the login process on any WordPress site running this plugin by sending a deliberately broken SAML signature. The plugin's code accepts the broken signature as valid — like a bouncer who waves you in because your fake ID looks close enough. An attacker can then log in as a full site administrator with no password at all.

Status: Patch available — update the plugin to version 17.0.6 or higher right away.

CVE-2026-61979 miniOrange SAML 2.0 WordPress Plugin HIGH 8.1

A second flaw in the same miniOrange plugin — this one causes "algorithm confusion," where the plugin can be tricked into accepting a login signed with the wrong security method. An unauthenticated attacker can exploit this to escalate their privileges and take over a WordPress site account, including administrator-level access.

Status: Patch available — update to version 17.0.5 (Standard edition) or 17.0.6 to cover both flaws.

🛠  New Tech
DecryptAds: A Free Tool That Shows Who's Really Tracking You Online

A new free service called DecryptAds (decryptads.com) lets anyone look up which advertising companies and data brokers are harvesting information from any website or app. It was built by Zach Edwards, chief research officer at Infoblox, along with two co-founders. The tool scrapes publicly available files that websites are supposed to publish — listing who's allowed to run ads or collect data on their visitors — and then cross-references them to reveal the full picture. A search for ESPN.com, for example, turned up 143 ad partners and 19 data brokers, including four firms based in Russia, China, or the UAE. DecryptAds also flags ad partners based in countries considered security risks, making it useful not just for privacy advocates but for anyone curious about who profits from their browsing habits.

↗ Krebs on Security
💡  Deep Dive
The Ad That Watched You Back: How the Online Ad Industry Became a Privacy Free-for-All

Every time you visit a website, dozens of companies you've never heard of may be collecting information about you — your location, your device, your browsing habits. Most people know ads exist. Far fewer people realize that behind each ad sits a sprawling, largely invisible web of data brokers, resellers, and ad networks, some of them based in countries that aren't exactly friendly toward the United States.

The new DecryptAds tool has pulled back the curtain on just how tangled this ecosystem really is. Take ESPN.com: it openly declares 143 advertising partners in its public ads.txt file. Nearly half of the data brokers listed are collecting precise location data from ESPN visitors. Four ad partners are based in Russia, China, or the UAE — including one firm called Between Digital, which processes payments through a Russian bank that's under U.S. sanctions. And Between Digital's fingerprints show up on around 55,000 other websites too. The problem isn't unique to ESPN. A look at major U.S. military news sites — Army Times, Air Force Times, Defense News — shows the exact same Russian and UAE-linked ad firms tracking their readers. Think about who reads those sites.

For regular people, this matters for a simple reason: the data these brokers collect doesn't stay in one place. It gets bought, sold, packaged, and resold — sometimes to advertisers, sometimes to insurers, sometimes to employers, and sometimes to governments. Your location data from a sports website can end up in places you'd never expect. And because this data flows through complex chains of resellers, it's nearly impossible to trace where it ends up. The new laws in California, Oregon, Texas, and Vermont requiring data brokers to register are a start — but registration alone doesn't stop the collection.

Watch for tools like DecryptAds to become more widely used by journalists, researchers, and regulators as the pressure grows to make the ad industry more accountable. In the meantime, using an ad blocker remains one of the most effective things you can do to limit how much of your data feeds into this system. It won't make you invisible — but it puts a significant dent in the pipeline.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →