<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/wordfence-security-news" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Wordfence Security News</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/wordfence-security-news</itunes:new-feed-url>
    <description>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.</description>
    <copyright>2012-2026 Defiant Inc. All Rights Reserved</copyright>
    <podcast:guid>294fd773-073d-5608-bb6d-08964562719f</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Thu, 04 Jun 2026 11:48:05 -0700</pubDate>
    <lastBuildDate>Thu, 04 Jun 2026 11:49:14 -0700</lastBuildDate>
    <link>https://www.wordfence.com</link>
    <image>
      <url>https://img.transistorcdn.com/Wq_-Nf8t4p9FMeTFUnB2VFtU_MTLRjwTzZznjj5L4hs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.jpg</url>
      <title>Wordfence Security News</title>
      <link>https://www.wordfence.com</link>
    </image>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:category text="Technology"/>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Wordfence</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/Wq_-Nf8t4p9FMeTFUnB2VFtU_MTLRjwTzZznjj5L4hs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.jpg"/>
    <itunes:summary>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.</itunes:summary>
    <itunes:subtitle>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape.</itunes:subtitle>
    <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
    <itunes:owner>
      <itunes:name>Wordfence</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>WooCommerce RCE | Drupal SQLi | Ghost CMS Clickfix Attack | Wordfence Security News | May 25, 2026</title>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>WooCommerce RCE | Drupal SQLi | Ghost CMS Clickfix Attack | Wordfence Security News | May 25, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">70825793-5d79-490f-a827-c27f32296fd1</guid>
      <link>https://share.transistor.fm/s/08da5955</link>
      <description>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 04 Jun 2026 11:48:05 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/08da5955/20fe2026.mp3" length="32996138" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UI7kcPE5qRmnipoU1z5frBy0E20sW5VgSRPA2DNqWq0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84M2Q3/MDQ2MzE0ODFkZmFk/YWNlOGRiN2ZlZGJk/NDljMy5qcGc.jpg"/>
      <itunes:duration>816</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Cybersecurity, WooCommerce, Drupal, Ghost CMS, Clickfix, WordPress, Wordfence Security News</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/08da5955/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1aa0cca5-dceb-4885-8986-74ef1f6ce4d4</guid>
      <link>https://share.transistor.fm/s/3a70d52d</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 22 May 2026 12:12:52 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/3a70d52d/75eabbe8.mp3" length="11548327" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/QU5gKsSkHuHvX_f6qPkLvD0Lxl6r_jBYmB9f78KqdEg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xOWYw/OGMxNWI0Yjg4ZjJh/MDQ4MGYxYzkzNzU4/ZDk2ZS5qcGc.jpg"/>
      <itunes:duration>700</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.json" type="application/json"/>
    </item>
    <item>
      <title>Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">14357644-5dad-4ca6-becb-94c4b91ddfc8</guid>
      <link>https://share.transistor.fm/s/55ee78c9</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 15 May 2026 17:13:28 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/55ee78c9/84d834cf.mp3" length="14653757" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/F_SxDuy1GIS5r5SUnpx68iLA1x_TZghpRX59g9-rUKY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZjVj/ZTIyYjYzY2ZiMTBj/NTFiYzg0MWZkMTJl/OTY2NS5wbmc.jpg"/>
      <itunes:duration>608</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.json" type="application/json"/>
    </item>
    <item>
      <title>Breeze Cache Mass Exploitation in 24 Hours | Bitwarden CLI Supply Chain Attack | ADT Confirmed in ShinyHunters Breach | Pack2TheRoot 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651) | Wordfence Security News | Week of April 27, 2026</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Breeze Cache Mass Exploitation in 24 Hours | Bitwarden CLI Supply Chain Attack | ADT Confirmed in ShinyHunters Breach | Pack2TheRoot 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651) | Wordfence Security News | Week of April 27, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bfe2b51b-9a74-43df-9c57-44587cffae87</guid>
      <link>https://share.transistor.fm/s/84b1ca75</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 04 May 2026 13:02:37 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/84b1ca75/eba96bb7.mp3" length="10454451" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MEBSIYp-7jnIsKnnx_rCPHTdcheyjKiWHFZaFkL0h9M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNGEz/YTM0OTdiNzY4NmJk/OWZiMzI3Mzg3N2Y1/M2I4Ny5wbmc.jpg"/>
      <itunes:duration>624</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/84b1ca75/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>WordPress 30+ Plugin Supply Chain Attack | Wordfence Security News | Week of April 13, 2026</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>WordPress 30+ Plugin Supply Chain Attack | Wordfence Security News | Week of April 13, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">056a29cd-c015-42cc-9bdc-992c54a63a6c</guid>
      <link>https://share.transistor.fm/s/170d5314</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 17 Apr 2026 14:18:02 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/170d5314/559faa1b.mp3" length="7873428" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/LQtcilkcSm2tBAJSVDhwQRFaLAtXbVC5RJDFVSlZWvI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNGYy/YmQ2OGUzZjQxMGVi/YWM5ZGQxODE2YTcz/YWNlMC53ZWJw.jpg"/>
      <itunes:duration>489</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription" type="text/html"/>
    </item>
    <item>
      <title>50,000 Site Ninja Forms File Upload Vulnerability | Anthropic Project Glasswing | Fortinet Zero Day | Wordfence Security News | April 6 2026</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>50,000 Site Ninja Forms File Upload Vulnerability | Anthropic Project Glasswing | Fortinet Zero Day | Wordfence Security News | April 6 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">643fca4d-7d3c-463f-b8a2-b323d27469ff</guid>
      <link>https://share.transistor.fm/s/48f55f81</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 10 Apr 2026 13:15:36 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/48f55f81/dbb20e4c.mp3" length="6688328" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Ip0_QMQKCxHynR1LOuRBN0htY3dkJaNka7HDLXzrlzE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMzI3/MzRiZGMwZDFkNjQ0/YWQ2NjY0MGQ0MDhh/ZTdlYi53ZWJw.jpg"/>
      <itunes:duration>415</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription" type="text/html"/>
    </item>
    <item>
      <title>MW WP Form 200K Sites at Risk | Axios Hack | Cisco Breach | Wordfence Security News | March 30, 2026</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>MW WP Form 200K Sites at Risk | Axios Hack | Cisco Breach | Wordfence Security News | March 30, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4ae3b264-9506-47d0-94db-896a7a593cb7</guid>
      <link>https://share.transistor.fm/s/3e16c17d</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 03 Apr 2026 12:15:22 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/3e16c17d/1b14a3b4.mp3" length="7118160" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/JF1HiIbDHNBvOPZZAE5s76YU8eLwKIjnAz0bY-y8m7I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMDgw/M2U1YzAwZTdkOGZh/OGQxZjk4NWQxZTk5/NWNiNy53ZWJw.jpg"/>
      <itunes:duration>442</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription" type="text/html"/>
    </item>
    <item>
      <title>Iran-Linked Hackers Breach FBI Director's Email | Wordfence Security News| Week of March 23, 2026</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Iran-Linked Hackers Breach FBI Director's Email | Wordfence Security News| Week of March 23, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">58833c10-09ed-49d3-aaab-152e0e62aa9e</guid>
      <link>https://share.transistor.fm/s/d9a87871</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Mar 2026 14:04:00 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/d9a87871/3a162eae.mp3" length="6361259" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/qoBjk1tfxmjKbg8VEBRV47nSJMfFo-vXI05QSmqgwXs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83Y2Ni/MTkwMjM4Nzc1ZDA2/ZjliMjIxMmFkMGYz/Mjc4Mi53ZWJw.jpg"/>
      <itunes:duration>395</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription" type="text/html"/>
    </item>
    <item>
      <title>30,000 Sites at Risk, Cisco Zero-Day &amp; Stryker Attack | Wordfence Security News | Week of Mar 9, 2026</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>30,000 Sites at Risk, Cisco Zero-Day &amp; Stryker Attack | Wordfence Security News | Week of Mar 9, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">08e87077-14c9-4622-b894-f31d76add52e</guid>
      <link>https://share.transistor.fm/s/60882fd7</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 13 Mar 2026 14:00:00 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/60882fd7/327d379d.mp3" length="5525345" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2qAiJI6oMaDilR9ZKIvjtF5_zDViH_fPv3L6USsuIYs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNmEz/ZTM4NDgyMjIyZDBh/MGQ1NGVjNzk4ZTVh/OTAyYy53ZWJw.jpg"/>
      <itunes:duration>343</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress News, WordPress Security News, WordPress, WordPress Security, Cybersecurity, Cybersecurity News</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription" type="text/html"/>
    </item>
  </channel>
</rss>
