CyberAware UK Weekly Recap: WordPress Flaws, Berlin Ransomware Refusal, and Android 17 Privacy

Welcome to our Sunday recap. This week has been busy, with new threats and some positive developments. Here's what you need to know.

The Numbers

Our monitoring service DarkWatch recorded over 413,000 captures, tracked more than 5,000 entities, and issued over 1,100 alerts. That's a lot of activity, and we're keeping an eye on five active targets, including onion versions of popular sites like Archive.is, Proton Mail, and DuckDuckGo. These are medium risk, meaning they're being monitored for potential scams.

Top Stories

Five critical WordPress plugin and theme flaws were discovered that could allow attackers to take over a website or execute code remotely. If you run a WordPress site, update everything now.

Berlin refused to pay hackers who stole data from the city's state network. This is a stance many experts support, as paying ransoms can encourage more attacks.

Two alleged hackers were arrested in Australia, showing that law enforcement is making progress.

We also saw a vulnerability in Cosmos EVM that was exploited even though developers knew about it, and a chain of two PaperCut flaws that allowed code execution without authentication.

Looking Ahead

Next week, we'll focus on protecting your online accounts and explore Android 17's new feature that hides your website visits from network providers — a big win for privacy.

Takeaway

Update your software today, especially if you use WordPress. And always verify site addresses before entering any personal information.