vulnerability Multiples vulnérabilités dans WordPress (20 juillet 2026) Multiple vulnerabilities have been discovered in WordPress, allowing attackers to execute arbitrary code remotely and bypass security policies. The CERT-FR has a public proof of concept demonstrating the impact. Users of… CERT-FR · Jul 20, 2026 High CVE-2026-60137CVE-2026-63030wordpressvulnerabilitysql injection
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
threat-intel Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks Google Threat Intelligence Group (GTIG) has identified a new backdoor, STOCKSTAY, developed and deployed by the Russian state-sponsored threat actor Turla. This multi-component backdoor, built using .NET and leveraging a… The Hacker News · Jun 26, 2026 High CVE-2025-8088UKITNEespionagebackdoorrussia
threat-intel New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new stealthy backdoor, Mistic (MLTBackdoor), linked to the KongTuke IAB has been used in financially motivated attacks targeting organizations across insurance, education, IT, and professional services since April 2026… The Hacker News · Jun 25, 2026 High USbackdoorremote access trojanclickfix
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
threat-intel Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign A sophisticated cybercrime campaign, orchestrated by unknown threat actors, is utilizing a multi-channel approach to distribute a cross-platform clipboard hijacker designed to steal cryptocurrency. The campaign leverages… Dark Reading · Jun 22, 2026 High USclipboard hijackingreputation manipulationcrypto theft
vulnerability Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys A vulnerability in the Gravity SMTP WordPress plugin has been exploited by attackers, allowing them to extract sensitive data such as API keys and configuration details from approximately 100,000 sites. The flaw, tracked… The Hacker News · Jun 20, 2026 Medium CVE-2026-4020USwordpressapicredentials
vulnerability Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin Hackers are actively exploiting a vulnerability in the Gravity SMTP WordPress plugin, allowing them to access sensitive information such as API keys and email service credentials. This flaw, tracked as CVE-2026-4020, has… BleepingComputer · Jun 19, 2026 Medium CVE-2026-4020CVE-2026-8713wordpressapicredentials
threat-intel Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites An international law enforcement operation, dubbed Operation Endgame, successfully disrupted SocGholish’s infrastructure and removed malware from nearly 15,000 WordPress websites. The takedown, involving agencies from mu… The Hacker News · Jun 19, 2026 High NLCADEbotnetwordpressmalware
supply-chain ShapedPlugin update flow hacked to infect WordPress sites A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pi… BleepingComputer · Jun 18, 2026 High CVE-2026-10735CVE-2026-49777wordpresssupply chainbackdoor
threat-intel The Top 10 Attack Surface Exposures in 2026 This article from The Hacker News details a study by Intruder analyzing 3,000 attack surfaces, revealing widespread vulnerabilities in organizations’ internet-facing services. A significant 60% of organizations had expos… The Hacker News · Jun 17, 2026 High attack-surfacevulnerabilitydatabase
threat-intel ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures ClickFix campaigns are expanding their malware delivery tactics with new loaders, including BabaDeda Loader, Lorem Ipsum Loader, and Storage Crypter, targeting education and financial organizations. These attacks utilize… The Hacker News · Jun 16, 2026 High RUBYsocial engineeringloaderpayload
threat-intel 'Lorem Ipsum' Malware Pivots to ClickFix Delivery The 'Lorem Ipsum' malware campaign, initially delivered via Trojanized Microsoft Teams installers, has shifted its tactics following Microsoft's disruption of the Fox Tempest malware-signing-as-a-service provider. Now, t… Dark Reading · Jun 16, 2026 High USclickfixwordpressshellcode
supply-chain OptinMonster WordPress plugin hacked in CDN supply-chain attack A supply-chain attack targeting the Awesome Motive CDN compromised WordPress plugins OptinMonster, TrustPulse, and PushEngage. Attackers gained access through a vulnerability in the UpdraftPlus plugin, leveraging the CDN… BleepingComputer · Jun 15, 2026 High UScdnwordpresssupply chain
malware Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites A security incident has been discovered affecting over 1.2 million WordPress sites using the PushEngage, OptinMonster, and TrustPulse plugins. An attacker tampered with the plugins' JavaScript files, creating backdoors t… The Hacker News · Jun 15, 2026 High CVE-2026-10795USwordpresscdnbackdoor
vulnerability Critical Everest Forms Pro flaw exploited to take over WordPress sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution,… BleepingComputer · Jun 6, 2026 Critical CVE-2026-3300wordpresspluginvulnerability
malware WordPress malware campaign hides payloads in Steam profiles A WordPress malware campaign has infected nearly 2,000 websites by hiding command-and-control (C2) data within Steam Community profile comments. The attackers utilize invisible Unicode characters to encode malicious payl… BleepingComputer · Jun 1, 2026 High USwordpresssteemunicode
threat-intel Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API A China-aligned threat actor known as Webworm has expanded its arsenal with two new backdoors, EchoCreep and GraphWorm, utilizing Discord and the Microsoft Graph API for command-and-control communications. The group, act… The Hacker News · May 20, 2026 High CHRUGEdiscordmicrosoft graphrat