Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
10 / 10 results
highperson_alertThreat ActorStopAndProtect Exploits 2,000 Hacked WordPress Sites for Malware Delivery
StopAndProtect is a global cybercrime operation tracked by Check Point Research since mid-May 2026. The operation is named after a ransomware family discovered during initial investigation.
highbug_reportVulnerabilityWordPress pre-auth XSS on login page enables RCE via admin interaction
WordPress CMS all versions prior to 7.0.3. Patches backported to 4.7 branch and newer. Versions older than 4.7 remain vulnerable and unpatched. Default installations affected; no special hosting configuration required.
criticalbug_reportVulnerabilityWordPress Core RCE flaws CVE-2026-63030, CVE-2026-60137 under active exploit
WordPress Core (specific versions not disclosed in advisory). Two remote code execution vulnerabilities (CVE-2026-63030, CVE-2026-60137) affecting the core platform.
criticalbug_reportVulnerabilityWordPress Core wp2shell flaws actively exploited for webshell deployment
WordPress Core (specific versions not disclosed). Both CVE-2026-63030 and CVE-2026-60137 affect core WordPress installations, enabling remote attackers to deploy webshells and malicious plugins.
criticalbug_reportVulnerabilityWordPress wp2shell flaws enable unauthenticated RCE, active exploitation
WordPress core (specific versions not disclosed). CVE-2026-63030 and CVE-2026-60137 must be chained for unauthenticated remote code execution. All unpatched WordPress installations are potentially vulnerable.
criticalbug_reportVulnerabilityWordPress Core RCE "wp2shell" exploits now public, patch immediately
WordPress Core (specific versions not disclosed in provided data). Vulnerability enables remote code execution. Public exploits available under the name "wp2shell".
criticalbug_reportVulnerabilityWordPress 6.9–7.0 unauthenticated RCE patched, forced auto-update active
WordPress core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. All sites running these versions are vulnerable to unauthenticated remote code execution via anonymous HTTP requests. Patched in 6.9.5 and 7.0.2.
highperson_alertThreat ActorSocGholish Infrastructure Disrupted in Operation Endgame Takedown
SocGholish is a threat actor known for compromising web infrastructure, particularly WordPress-based content management systems, to facilitate malware distribution and drive-by download attacks.
highperson_alertThreat ActorEvil Corp SocGholish botnet dismantled: 15,000 sites, 100+ servers
Evil Corp (also tracked as Indrik Spider, Manatee Tempest, DEV-0243, UNC2165) is a financially motivated cybercrime group linked to Russia. The group has operated since at least 2014 and is known for deploying banking trojans and ransomware variants…
highbug_reportVulnerabilityMalware campaign infects 2,000 WordPress sites using Steam profiles for C2
Nearly 2,000 WordPress websites compromised. All WordPress versions potentially affected depending on initial infection vector (likely vulnerable plugins, themes, or weak credentials).