WordPress Ends Security Updates for Versions 4.1 Through 4.6
WordPress will stop providing security updates for versions 4.1 through 4.6 as of July 2025, urging remaining users to upgrade.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,126 stories synthesized.
WordPress will stop providing security updates for versions 4.1 through 4.6 as of July 2025, urging remaining users to upgrade.
The threat group 'The Com' is exploiting Salesforce app authorization abuse through social engineering, targeting tenants for data theft and extortion.
GitLab released versions 18.0.2, 17.11.4, and 17.10.8 on June 11, 2025, fixing multiple security vulnerabilities including three high-severity issues that could enable account takeover, cross-site scripting, and malicious CI/CD job injection.
Jenkins released a security advisory for a high-severity XSS vulnerability in the Gatling plugin that bypasses CSP protections, with no fix currently available.
A threat actor group with tactics similar to Scattered Spider is hijacking DNS MX records to redirect enterprise email traffic to attacker-controlled servers, enabling credential theft and network compromise within minutes.
GitLab released versions 18.0.1, 17.11.3, and 17.10.7 on May 21, 2025, fixing multiple security vulnerabilities including a high-severity unauthenticated denial-of-service flaw and a SAML response manipulation bug that bypasses two-factor authentication.