August 2, 2026
- Backdoor planted in the ARVE WordPress plugin. Wordfence found a hardcoded-token backdoor in ARVE v10.8.7 (CVE-2026-18072) granting full admin access; the plugin was pulled from WordPress.org after detection (Hackread). · Vulnerabilities & Exploits
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves