
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
by info@thehackernews.com (The Hacker News) on September 4, 2026 at 3:57 pm
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
by info@thehackernews.com (The Hacker News) on September 4, 2026 at 3:20 pm
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
by info@thehackernews.com (The Hacker News) on September 4, 2026 at 2:51 pm
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
by info@thehackernews.com (The Hacker News) on September 4, 2026 at 8:48 am
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
by info@thehackernews.com (The Hacker News) on September 4, 2026 at 7:35 am
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users