supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The attack exploited a cross-site scripting (XSS) vulnerability in the vendor’s internal API, leading to th… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss
threat-intel Planity visée par une vente présumée de données piratées A hacker is offering a database allegedly containing information on nearly a million people linked to Planity, a platform connecting users with beauty and wellness professionals. Planity acts as an intermediary, facilita… ZATAZ · Jul 30, 2026 Medium data breachphishingdata leak
vulnerability Unpatched Fastjson Vulnerability Exploited in Attacks A critical remote code execution (RCE) vulnerability in Fastjson, a popular Java JSON processing library, has been actively exploited by threat actors. The vulnerability, tracked as CVE-2026-16723, allows attackers to ex… SecurityWeek · Jul 28, 2026 Critical CVE-2026-16723USSGCArcejsonspring boot
vulnerability Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available A critical Remote Code Execution (RCE) vulnerability in Fastjson 1.x, a Java JSON library by Alibaba, is being actively exploited. Attackers are leveraging a type-resolution path to execute arbitrary code in Spring Boot… The Hacker News · Jul 25, 2026 High CVE-2026-16723USSGCArcejsonjava
vulnerability Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A researcher, depthfirst, has published a proof-of-concept exploit targeting GitLab 18.11.3 and earlier, allowing authenticated users to execute arbitrary commands as the ‘git’ user. The vulnerability stems from flaws wi… The Hacker News · Jul 25, 2026 High rcejupyterjson
threat-intel Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library A typosquatted version of the Newtonsoft.Json library has been discovered, designed to rig live game results on Digitain, an online betting platform. The package, disguised as a legitimate library, exfiltrates rigged dat… The Hacker News · Jul 22, 2026 High NOtyposquattingriggingexfiltration