Author: InfoForTech

Ravie LakshmananJun 20, 2026Vulnerability / Web Security Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that’s installed on about 100,000 sites. The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens configured for the plugin’s email integrations. “This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it,” Wordfence said. “When the ?page=gravitysmtp-settings query parameter is…

Read More

With three hawker concepts under its belt, JOFA is looking to operate its own coffee shop next Most hawkers spend years perfecting a single stall. But for Joel Tan (30), Fabian Lim (30), and Liang Jun Hao (31), one concept was never the end goal. From one mee pok stall in Tampines, the trio has built a business with multiple concepts, including Western food, Japanese rice bowls, and soon, their own coffee shop. Along the way, they’ve had their fair share of wins and setbacks, from expanding to new outlets to losing over S$70,000 on a poorly chosen location. Vulcan…

Read More

Sony has filed a PSN login patent, first spotted by RespawnFirst, that would pull the DualSense controller into the sign-in process. A PlayStation console would start the request, then the controller would help confirm that the account holder is close enough to approve access. For players, the appeal is easy to see. PSN account abuse can lead to unauthorized purchases, lost access, and attempts to resell established accounts. Sony already offers 2-step verification and passkeys, but this idea adds a hardware check to the login chain. How would the controller approve access WIPO The patent describes a handoff that begins…

Read More

The era of hacking corporate databases may be giving way to something far more direct. Have I Been Pwned has added a massive collection of infostealer malware records containing 124 million passwords and 56 million email accounts. The credentials came from stealer logs created by malware that harvests sensitive information from infected devices. The dataset offers a snapshot of how cybercriminal tactics are evolving. As infostealer malware becomes more widespread, attackers are increasingly bypassing organizations altogether and collecting credentials directly from users, creating fresh and simpler opportunities for account takeovers and broader cyberattacks. What happened and why it matters The…

Read More

Protesters outside the Spheres on Amazon’s Seattle campus Thursday evening. (GeekWire Photo / Todd Bishop) Carrying bullhorns and signs depicting Amazon executives as war criminals, about two dozen people protested outside the Amazon Spheres in Seattle on Thursday evening, calling on the company to stop providing technology to Israel for what they described as genocide in Gaza. The protesters said they were trying to disrupt what they believed to be a gathering of Amazon executives, state and local leaders, U.S. State Department officials and Australian government representatives on an upper floor of the Spheres, on the eve of the World…

Read More

“We thought that’s probably the one that’s least likely to pop up,” Geisbert says. “We guessed wrong.”Concerned by that knowledge gap, in 2011 he decided to modify a vaccine, which led to the crab-eating macaque study. In the same study, he also finally tested a blend of existing ebola vaccines on the Bundibugyo strain, but they didn’t provide 100-percent protection.If the 2012 outbreak had occurred after the major Zaire outbreak, Geisbert says, it’s possible pharmaceutical companies might’ve been more keen to commercialize a vaccine that protects against the Bundibugyo strain.But with the present outbreak rivaling the 2013 to 2016 one…

Read More

Find out exactly how a real attacker would break into your network, application, or cloud environment, before they do. Our certified ethical hackers combine manual exploitation with industry-standard methodology (PTES, OWASP, NIST) to deliver evidence-based findings your board, your auditor, and your IT team can all act on. Get a free scoping call →  |  Typical turnaround: 2–4 weeks  |  POPIA & PCI DSS-ready reporting What Is Penetration Testing? Penetration testing, often shortened to “pen testing,” is an authorised, simulated cyberattack against your own systems, carried out by a qualified human tester rather than software alone. The objective is straightforward:…

Read More

Companies working at the frontier of aerospace, energy, and computing are constantly looking for new materials to improve performance. But in order to understand how those materials will actually behave once they’re inside rockets or on computer chips, companies first have to make the material and then test it. That’s because even the most powerful simulation techniques struggle to model the complex chemical arrangements in most of today’s solid materials. The problem adds costs and time to materials innovation.Now a team of MIT researchers has created a way to accurately model the behavior of metals, regardless of the complexity of…

Read More

AI is rapidly gaining abilities that once belonged to humanity alone. In just the past four years, chatbots have learned how to build apps, make video games, generate research reports, compose songs, analyze contracts, and write terrible literary fiction. Soon, they may even be able to dread their own deaths.In Silicon Valley, many believe that AI systems can already think and feel. Geoffrey Hinton, the pioneering computer scientist and “godfather” of modern artificial intelligence, thinks that today’s large language models (LLMs) are conscious. Anthropic CEO Dario Amodei is “open to the idea” that Claude has a subjective experience — while…

Read More

The U.S. Federal Energy Regulatory Commission has issued a set of orders designed to expedite data center projects. The agency’s five commissioners unanimously approved the directives on Thursday. The orders are part of an initiative that U.S. Energy Secretary Chris Wright launched last year to streamline data center construction. According to the Associated Press today, it’s believed that additional measures could follow suit down the line. The Federal Energy Regulatory Commission, or FERC, supervises interstate energy transmission infrastructure. The directives it issued on Thursday apply to the six largest interstate power grid operators in the US. Those organizations provide electricity to…

Read More