Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.
"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said.
The
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
The vulnerabilities in question are -
CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms β Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.
The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.
"We recommend all server owners and Desktop users
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
OpenAI on Thursday officially unveiled GPTβ6 Astra, which it described as the "world's most intelligent and aligned model."
The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.
"Astra is state-of-the-art on computer use, browsing, software engineering,