We are a collective of digital rights advocates, security experts, and educators committed to empowering individuals and communities with the knowledge and tools to protect their digital freedoms.
How we work to protect digital rights and empower communities
Raising awareness about digital rights, privacy threats, and security best practices.
Advocating for policies and regulations that protect digital rights and freedoms.
Providing training and resources on digital security for vulnerable groups.
Offering direct assistance to individuals and organizations facing digital threats.
Creating networks of digital rights defenders to share knowledge and resources.
Working with partners globally to develop solutions to digital security challenges.
Latest WordPress security vulnerabilities affecting plugins, themes, and core.
Published Date: Apr 8, 2026
The Advanced Contact Form 7 DB plugin is susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities in versions up to and including 2.0.9. This flaw allows unauthenticated attackers to potentially manipulate form entries by deceiving a site administrator into executing specific actions.
Published Date: Apr 8, 2026
The Advanced Contact Form 7 DB plugin up to version 2.0.9 allows unauthorized data exports due to insufficient user permission checks. Authenticated attackers with Subscriber-level access can exploit this flaw to export form submissions.
Published Date: Apr 7, 2026
The Ninja Forms - File Uploads plugin for WordPress is affected by a vulnerability that allows arbitrary file uploads, which can lead to remote code execution. This flaw is present due to the lack of file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function, impacting versions up to 3.3.26.
Stay informed about the latest digital rights issues, threats, and community resources
Anthropic's newly unveiled AI model, Mythos, represents a significant advancement at the intersection of artificial intelligence and cybersecurity. Specifically designed to identify critical security vulnerabilities, Mythos has the astonishing capability to discovery flaws, some of which have been lurking unnoticed for decades. The profound impact of such technology could revolutionize digital security frameworks across the globe by preemptively addressing these vulnerabilities before they are exploited by malicious entities. However, with great power comes great responsibility, and the possibilities of its misuse have led to Anthropic's decision to hold back a public release. Instead, the standout AI model is currently being evaluated by a selected group of around 40 companies, including tech giants, who are assessing it for wider private deployment. These companies' early involvement aims to harness Mythos's capabilities to patch vulnerabilities and safeguard systems against future threats proactively. The closed testing phase presents a strategic move to strike a balance between unleashing machine learning's potential for safeguarding digital infrastructures while also curbing chances of adversarial manipulation. As the landscape of threats evolves, tools like Mythos could become essential elements in the comprehensive arsenal required for robust digital security.

In recent cybersecurity news, an alarming zero-day vulnerability, dubbed BlueHammer, has surfaced, targeting Windows systems. The exploit allows attackers to gain elevated privileges on a host machine, potentially leading to full system compromise. This proof-of-concept (PoC) exploit was released on GitHub by an individual using the pseudonyms Chaotic Eclipse and Nightmare Eclipse. Although the exploit is in an early stage and noted to be buggy, its leak on a public platform heightens the risk of it being weaponized by malicious actors. Zero-day vulnerabilities are critical because they exploit previously unknown software flaws, leaving no time for the vendor to provide a patch before attacks can occur. This revelation has rattled the cybersecurity community, as privilege escalation vulnerabilities are particularly dangerous in corporate settings where the potential for data breaches is significant. Microsoft has yet to release a patch, leaving systems exposed and users reliant on interim mitigation techniques such as disabling features exploited by the vulnerability. The incident underscores the pressing need for robust security practices and emphasizes the importance of staying informed about immediate cybersecurity threats.

Cloudflare's introduction of 'EmDash' marks a significant evolution in the realm of content management systems (CMS), positioning itself as a futuristic alternative to WordPress. Built with a focus on security, scalability, and AI-native workflows, EmDash is designed to address several critical needs in the modern digital landscape. Unlike traditional platforms, EmDash promises a robust infrastructure that natively integrates artificial intelligence to enhance operational efficiency and user engagement. As cyber threats evolve and become more sophisticated, EmDash aims to offer a proactive stance in ensuring that user data and content integrity are preserved against breaches. This new CMS highlights features such as automated security updates, seamless integrations with AI tools, and a modular architecture that caters to modern web development needs. Cloudflare’s EmDash is anticipated to foster a safer, more dynamic online ecosystem by providing developers and content creators with the tools necessary to build resilient digital experiences. This shift towards a more AI-integrated CMS aligns with the broader industry trend of adopting machine learning and AI to drive smarter, safer, and more effective online solutions.
Join us in defending digital rights and protecting vulnerable communities.
Get in touch to discuss your needs or how you can support our mission
We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies.