Thousands of websites using WordPress continue to be vulnerable to a critical security flaw in a plugin named Hunk Companion. The flaw, which has been actively exploited in attacks that execute malicious code, has a severity rating of 9.8/10. Less than 12% of users have installed the patch, leaving around 9,000 sites at risk.

LockBit ransomware group falls victim to hackers itself
A data leak has disclosed information about negotiations with victims, Bitcoin wallet addresses, affiliate accounts, and details of attacks.