Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

One Dead Container Stopped nginx From Starting At All

Eight containers behind one nginx. One of them was stopped. nginx would not start. Not "returned 502 for that service" — would not start, at all, with every other service running fine: host not found…

  • One container failure caused nginx to fail starting up
  • Nginx caching DNS couldn't adapt to container's changing IP
  • Fix involves deferring DNS resolution, using Docker's embedded DNS

More from Tuesday 25 August →