July 31, 2026
- VaahCMS 2.0.0–2.3.4 (CVE-2026-67595) shipped malicious obfuscated JavaScript embedded in an OTP email template that phones home to a C2, logs passwords, scrapes WhatsApp Web, and can remotely alter pages — a backdoor in the product itself (commit). · Vulnerabilities & Exploits
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests