September 16, 2026
- Acronis and WooCommerce components are both under active attack. Acronis warned of exploitation against its cPanel backup plugin (BleepingComputer). A separate campaign is exploiting WooCommerce Wholesale Lead Capture to upload PHP backdoors to WordPress sites (BleepingComputer).
· Vulnerabilities & Exploitation
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
September 4, 2026
in Malware That Gaslights the AI Analyst
August 30, 2026
- WordPress 7.1 fixes an Author-role path to arbitrary file deletion — poisoning attachment metadata in media finalize requests to bypass containment checks, up to and including
wp-config.php (HackerOne) — plus a stored XSS in wp-admin media from unsanitised sub_sizes[].file (HackerOne). Five further critical plugin and theme flaws enabling takeover or RCE are rounded up by The Hacker News.
· Vulnerabilities & Exploitation
in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited
August 28, 2026
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 25, 2026
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 21, 2026
in Microsoft's Own Defender Driver Becomes the EDR Killer
August 20, 2026
- StopAndProtect runs on nearly 2,000 hacked WordPress sites used as delivery, C2, and storage for stolen documents and screenshots, with persistence via malicious plugins and over 6,000 victim IPs; operator opsec lapses exposed the campaign's scale (Check Point Research).
· Threat Intelligence
in Feds Say AI-Written Exploit Code Is Already Hitting Siemens PLCs
August 17, 2026
- Forminator WordPress plugin unauthenticated RCE (CVE-2026-15748, CVSS 9.8). Malicious PHP uploads can achieve arbitrary code execution across 600,000+ installs (The Hacker News).
· Vulnerabilities & Exploits
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 8, 2026
- WordPress patched XSS2Shell (CVE-2026-64638), a CVSS 8.9 pre-auth reflected XSS in the login screen that chains to PHP RCE. The XSS needs no account; researchers at pwn.ai — who say the bug was discovered autonomously — showed it chaining to code execution when a logged-in admin interacts with an attacker page (create API creds, gain REST access, upload a malicious plugin). The flaw affects every version of WordPress. The Hacker News
· Vulnerabilities & Exploits
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 2, 2026
- Backdoor planted in the ARVE WordPress plugin. Wordfence found a hardcoded-token backdoor in ARVE v10.8.7 (CVE-2026-18072) granting full admin access; the plugin was pulled from WordPress.org after detection (Hackread).
· Vulnerabilities & Exploits
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
July 23, 2026
- WordPress wp2shell — detection and hunt guidance shipped. As the pre-auth RCE chain (CVE-2026-63030 route-confusion + CVE-2026-60137 SQLi) stays under active exploitation (earlier coverage), Elastic Security Labs published an end-to-end walkthrough with detection rules, IOCs and hunt queries (Elastic) (discussion).
· Vulnerabilities & Exploits
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- WordPress "wp2shell" exploitation continues to broaden into mass scanning and webshell deployment. Wiz and BleepingComputer report attackers chaining CVE-2026-63030 and CVE-2026-60137 for unauthenticated RCE and persistent webshells; NCSC-FI has amplified the exploitation warning (earlier coverage). Wiz, BleepingComputer.
· Vulnerabilities & Exploits
- The DPRK npm supply-chain campaign added more packages, with Nextron flagging
vectormark v1.0.0 and rollup-packages-polyfill-core v0.13.9 (which silently installs vectormark). The three-stage, RC4-encrypted payload pulls obfuscated JS from api[.]avax-test[.]dev and steals SSH keys, AWS credentials, Docker tokens, .env files, and git history (earlier coverage). Nextron.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 21, 2026
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 20, 2026
- Hugging Face's July intrusion was, per its own account, executed entirely by an autonomous AI agent system that abused malicious datasets to reach code-execution paths. Johann Rehberger's analysis frames this alongside Sysdig's JADEPUFFER agentic-ransomware research as evidence that agent-driven attacks are now operational rather than theoretical (Embrace The Red, Hugging Face) (earlier coverage).
· AI & Model Security
- wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage).
· Vulnerabilities & Exploits
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 19, 2026
- WordPress "wp2shell" (CVE-2026-63030) is now weaponized. Multiple researchers — including Assetnote's hash_kitten and teams at calif.io and FullHunt — have reproduced the unauthenticated REST API batch-route confusion chain that yields RCE against default installs, and public PoCs are circulating. Advice has shifted from "patch" to "patch and consider vulnerable systems compromised." Fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (BleepingComputer, FullHunt analysis + scanner, NCSC-NL) (earlier coverage) (discussion).
· Vulnerabilities & Exploits
in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation
July 18, 2026
- "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST
/batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory.
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
June 22, 2026
A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.