Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Emerging Threat: (CVE-2026-10818) WPForms Pro Arbitrary File Upload Leading to Remote Code Execution

CVE-2026-10818 is an arbitrary file upload vulnerability in WPForms Pro, the paid edition of a widely deployed WordPress form builder plugin. It was published on July 25, 2026, with Wordfence as the assigning CNA. The flaw sits in the ajax_chunk_upload_finalize function, which handles the final step of a chunked file upload. File type validation runs after the chunk metadata and the file contents have already been written to disk, and the assembled file is not deleted when that validation fails.

CrowdStrike Joins the Open Secure AI Alliance to Advance AI Safety and Security

AI is changing the speed and scale of cyber defense, and the speed and scale of the adversary. As AI becomes embedded across government, critical infrastructure, and enterprise environments, defenders need the ability to inspect, test, adapt, and secure the systems they depend on.

Why AI Security Has to Live at the Decision Point

For the past couple of years, most of the industry’s attention has gone toward agents that respond to a single prompt. They ask a question, get an answer, and move on. Enterprises are now deploying long-horizon agents; autonomous systems that execute extended, multi-step tasks across hours or days, without a human checking in on every step. These agents plan, reason, and improvise their way toward a goal, and that changes what security has to protect against.

We're open-sourcing our privacy proxy CLI

Debugging privacy-preserving protocols is hard. Oblivious HTTP has several different steps across four different parties, not to mention binary HTTP encoding and details spread across many draft RFCs. We've taken what we've learned operating protocols like Oblivious HTTP at the scale of millions of requests per second, and wrapped it up in a nice, clean CLI tool — that we are open-sourcing today. We call it our privacy-client, or pvcli.

Top 10 Log Aggregation Tools for 2026: SIEM & Compliance

You're staring at a growing pile of endpoint, cloud, firewall, and identity logs, and the question isn't whether the data is useful, it's whether you can turn it into evidence, detections, and a defensible audit trail. In regulated environments, HIPAA, PCI, and CMMC don't care that your team is busy, they care that logs are collected consistently, normalized correctly, retained properly, and searchable when an incident or audit hits.