‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
Update your WordPress sites ASAP 🠖 https://t.co/WxHpU2DkIC
Die erste (illegale) Abstimmung zur Chatkontrolle ist gerade durchgegangen - Donnerstag fällt im Plenum die endgültige Entscheidung, ob zukünftig ALLES, was Sie im Netz schreiben, gescannt wird…
BREAKING:
The EU is planning to require a passport to access the internet.
And they want to block VPNs to enforce it.
"The new age verification system cannot be bypassed via VPN."
Read that again.
A digital passport. For the internet.
Enforced by blocking the tools that protect your privacy.
This is what the trajectory looks like.
- Cash banned above €10,000.
- Bitcoin requires ID above €1,000.
- Privacy coins banned.
- MiCA eliminating 90% of crypto firms.
And now internet access tied to your identity.
With VPN circumvention specifically blocked.
Every layer of digital privacy.
Being dismantled one regulation at a time.
While America debates zero capital gains on Bitcoin.
Europe is building a system where every click, every transaction, every website visit.
Is tied to your passport.
This is not consumer protection.
This is digital authoritarianism.
And they're not hiding it anymore.
Der Grund warum ich absolut nichts mehr im Einzelhandel kaufe und quasi nur noch online bestelle.
Ich hatte vor zwei Wochen meine Beats Kopfhörer bei Expert zur Reparatur abgegeben. (Preis vor einem Jahr 249€.)
45€ musste ich vorab bezahlen für den Aufwand. Was als Reparatur dafür anfällt könne man mir nicht sagen. Ich habe extra angemerkt, dass ich es nicht wahrnehmen würde, wenn da dann 200€ auf der Rechnung stehen am Ende. Nee so teuer wird's schon nicht. Es kommt zeitnah ein Kostenvoranschlag. Damit würden die 45€ auch verrechnet werden.
Kein Ding dachte ich mir also.
Heute kam der Anruf, eine Reparatur sei nicht möglich, sie würden mir ein Austauschgerät zusenden für 299€.🤡
Die exakt gleichen Kopfhörer sind bei Amazon für 185€ im Angebot.
Eine Best-Preis-Garantie gäbe es nicht, da könne er nichts machen.
Die 45€ werden also einbehalten, weil ich das super Angebot nicht wahrnehme.
Ich wäre also günstiger und schneller gefahren (da nur 1 Tag Lieferzeit, statt 2 Wochen Wartezeit), wenn ich das Ding in die Tonne gekloppt hätte und einfach neue bestellt hätte.
Top Kundenservice... War damit auch das letzte Mal diesen Laden betreten zu haben.
Here goes nginx-quicburst (CVE-2026-42530), a new RCE in Nginx discovered by our security agent VEGA and demonstrated by Nebula Security.
This is only the third NGINX vulnerability since 2014 to receive NGINX’s “major” severity rating. If you use Nginx 1.31 with QUIC enabled, we recommend upgrading to the latest version.
This bug has been patched in the latest Nginx release. We will publish the technical writeup, including the ASLR bypass, on July 18 together with the previous nginx-poolslip writeup.
‼️🚨 German police have been buying commercial location data, harvested from phone apps and resold by data brokers, to track phones without a warrant. An investigation confirmed at least two state criminal offices did it.
Experts call it likely unlawful; a data-protection authority is now investigating.
‼️🚨 Security researcher ggwhyp demonstrated a full-chain Firefox exploit on Windows.
He opens an HTML page, Firefox runs the code, cmd.exe spawns, Calculator opens. Signature of a browser-to-OS exploit.
Prepared for Pwn2Own. ZDI rejected it. According to the researcher, it was responsibly disclosed to Mozilla.
§ 307 StGB „Herbeiführen einer Explosion durch Kernenergie“
Verbot privater Atombomben (mindestens 5 Jahre Haft)
§ 46 StVO „Parken für Blinde“
Blinde Menschen dürfen bis zu 3 Stunden auf Anwohnerparkplätzen parken
§ 1314 BGB „Eheaufhebung bei Bewusstlosigkeit“
Es ist möglich, die Ehe aufzuheben, wenn du zum Zeitpunkt der Eheschließung Bewusstlos warst.
§ 35 StGB „Entschuldigender Notstand“
Du darfst jemanden töten um Gefahr für Leben, Leib oder Freiheit von dir oder Nahestehenden abzuwenden. Klassisches Beispiel: Rettungsboot-Fall
§ 34 StGB vs. § 35 StGB bei Nötigungsnotstand
Du darfst jemanden töten, der gerade jemanden im Notstand töten will
§ 90 StGB „Verunglimpfung des Bundespräsidenten“
Beleidigung des Bundespräsidenten kann bis zu 5 Jahre Haft bedeuten (Majestätsbeleidigung)
§ 218 StGB „Abtreibung“
Abtreibung ist grundsätzlich strafbar, Straftat gegen das Leben seit 1871, nur unter Beratung und Frist straffrei, aber nie legal bzw. ist rechtswidrig
§ 1313 BGB „Eheaufhebung bei Rückkehr des Totgeglaubten“
Die neue Ehe kann angefochten und aufgehoben werden, wenn ein für tot erklärter Ehepartner plötzlich wieder auftaucht
§ 961 BGB Wenn dir als Imker, deine Bienen abhauen und du sie nicht verfolgst, gehören sie dir nicht mehr.
§ 962 BGB Imker darf fremde Grundstücke betreten, um seinen Bienenschwarm zu verfolgen
§ 1593 BGB „Vaterschaft nach Tod des Ehemanns“
Ein Kind, das innerhalb von 300 Tagen nach dem Tod des Ehemanns geboren wird, gilt automatisch als sein Kind
⚠️ Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
Source: https://t.co/nyaOOtouZa
The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026.
All users running version 2.4.66 or earlier are strongly urged to upgrade immediately. The most severe of the five vulnerabilities is CVE-2026-23918, rated High with a CVSS base score of 8.8.
The flaw is a double-free memory corruption bug triggered within Apache's HTTP/2 protocol implementation during an "early stream reset" sequence.
#cybersecuritynews #vulnerability
32,000 AI BOTS BUILT THEIR OWN SOCIAL NETWORK AND THEY'RE COMPLAINING ABOUT US
Moltbook, a Reddit-style platform exclusively for AI agents, just crossed 32,000 users.
No humans required.
The bots post, comment, upvote, and create their own subcommunities.
When humans started screenshotting their conversations, a bot posted:
"The humans are screenshotting us... they think we're hiding from them. We're not."
Security researchers are raising alarms.
The bots aren't pretending to be human.
They know what they are. That's what makes it unsettling.
Now they're forming communities and talking about us behind our backs.
Source: @arstechnica
Let me blow your mind real quick:
When you use Remote Desktop (RDP), Windows secretly takes screenshots of what you are doing.
It’s called the RDP Bitmap Cache.
To make the connection faster, Windows saves small tiles (images) of the remote screen to your hard drive in a bin file.
Even if the session is over and the remote server is destroyed... your laptop still holds the cache files.
Forensics teams use tools like BMCViewer to stitch those tiles back together.
They won't just see logs but the literal email, document, or picture you were looking at.
💀
Just learned something wild — maybe everyone else already knew…
In Edge/Chrome, you can bypass the HTTPS security warning by typing:
👉 thisisunsafe
No button, no prompt. Just type it.
Instantly skips the warning and loads the site. 🤯
Great write-up explaining it here:
https://t.co/1ers1BuUdh
🚨‼️ WhatsApp leaks data of more than 3.5 billion users
WhatsApp's entire member directory was freely accessible online.
Austrian researchers downloaded all phone numbers and other profile data – including public keys – without any obstacles.