daily cyber × ai intelligence

index

tagged

[wordpress]

17 editions · 19 items

August 30, 2026

  • WordPress 7.1 fixes an Author-role path to arbitrary file deletion — poisoning attachment metadata in media finalize requests to bypass containment checks, up to and including wp-config.php (HackerOne) — plus a stored XSS in wp-admin media from unsanitised sub_sizes[].file (HackerOne). Five further critical plugin and theme flaws enabling takeover or RCE are rounded up by The Hacker News. · Vulnerabilities & Exploitation

in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited

August 8, 2026

  • WordPress patched XSS2Shell (CVE-2026-64638), a CVSS 8.9 pre-auth reflected XSS in the login screen that chains to PHP RCE. The XSS needs no account; researchers at pwn.ai — who say the bug was discovered autonomously — showed it chaining to code execution when a logged-in admin interacts with an attacker page (create API creds, gain REST access, upload a malicious plugin). The flaw affects every version of WordPress. The Hacker News · Vulnerabilities & Exploits

in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold

July 22, 2026

  • WordPress "wp2shell" exploitation continues to broaden into mass scanning and webshell deployment. Wiz and BleepingComputer report attackers chaining CVE-2026-63030 and CVE-2026-60137 for unauthenticated RCE and persistent webshells; NCSC-FI has amplified the exploitation warning (earlier coverage). Wiz, BleepingComputer. · Vulnerabilities & Exploits
  • The DPRK npm supply-chain campaign added more packages, with Nextron flagging vectormark v1.0.0 and rollup-packages-polyfill-core v0.13.9 (which silently installs vectormark). The three-stage, RC4-encrypted payload pulls obfuscated JS from api[.]avax-test[.]dev and steals SSH keys, AWS credentials, Docker tokens, .env files, and git history (earlier coverage). Nextron. · Threat Activity

in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face

July 21, 2026

in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live

July 20, 2026

  • Hugging Face's July intrusion was, per its own account, executed entirely by an autonomous AI agent system that abused malicious datasets to reach code-execution paths. Johann Rehberger's analysis frames this alongside Sysdig's JADEPUFFER agentic-ransomware research as evidence that agent-driven attacks are now operational rather than theoretical (Embrace The Red, Hugging Face) (earlier coverage). · AI & Model Security
  • wp2shell exploitation broadened in the wild. SecurityWeek confirmed active attacks against CVE-2026-63030 and CVE-2026-60137 shortly after disclosure, and NCSC-FI's Daniel Card reported live batch-route exploitation attempts (most failing against auto-patched or WAF-fronted sites; ~20% of a 3.5K-host sample was still unpatched). Eye Security published a defender's guide with forensic artifacts, a compromise-scanner plugin, and a browser extension to check patch status (SecurityWeek, PwnDefend, Eye Security) (earlier coverage). · Vulnerabilities & Exploits

in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap

July 19, 2026

  • WordPress "wp2shell" (CVE-2026-63030) is now weaponized. Multiple researchers — including Assetnote's hash_kitten and teams at calif.io and FullHunt — have reproduced the unauthenticated REST API batch-route confusion chain that yields RCE against default installs, and public PoCs are circulating. Advice has shifted from "patch" to "patch and consider vulnerable systems compromised." Fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (BleepingComputer, FullHunt analysis + scanner, NCSC-NL) (earlier coverage) (discussion). · Vulnerabilities & Exploits

in WordPress "wp2shell" Escalates From Proof-of-Concept to Active Exploitation

July 18, 2026

  • "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST /batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory. · Vulnerabilities & Exploits

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

June 22, 2026

Unpatchable iPhone BootROM Exploit Drops as a New Call-Stack Bypass Defeats 2024-Era EDR

A usbliter8 BootROM exploit for Apple A12/A13 devices and the LACUNA Chain EDR evasion technique represent major offensive advances, while Klue's OAuth token-theft incident exposed Salesforce customers to the Icarus actor. Supply-chain threats include a malicious node-fetch-utils npm package deploying fileless Python implants and active exploitation of CVE-2026-4020 in Gravity SMTP WordPress plugin.