ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Attackers are exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin to forge SAML responses and log in as administrators. The flaws were disclosed and fixed in July, but paid editions lacked alerts.
Tracked by ByteBrief