<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="/stylesheet.xsl" type="text/xsl"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:podcast="https://podcastindex.org/namespace/1.0">
  <channel>
    <atom:link rel="self" type="application/rss+xml" href="https://feeds.transistor.fm/wordfence-security-news" title="MP3 Audio"/>
    <atom:link rel="hub" href="https://pubsubhubbub.appspot.com/"/>
    <podcast:podping usesPodping="true"/>
    <title>Wordfence Security News</title>
    <generator>Transistor (https://transistor.fm)</generator>
    <itunes:new-feed-url>https://feeds.transistor.fm/wordfence-security-news</itunes:new-feed-url>
    <description>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.</description>
    <copyright>2012-2026 Defiant Inc. All Rights Reserved</copyright>
    <podcast:guid>294fd773-073d-5608-bb6d-08964562719f</podcast:guid>
    <podcast:locked>yes</podcast:locked>
    <language>en</language>
    <pubDate>Fri, 31 Jul 2026 11:41:02 -0700</pubDate>
    <lastBuildDate>Fri, 31 Jul 2026 11:41:42 -0700</lastBuildDate>
    <link>https://www.wordfence.com</link>
    <image>
      <url>https://img.transistorcdn.com/Wq_-Nf8t4p9FMeTFUnB2VFtU_MTLRjwTzZznjj5L4hs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.jpg</url>
      <title>Wordfence Security News</title>
      <link>https://www.wordfence.com</link>
    </image>
    <itunes:category text="News">
      <itunes:category text="Tech News"/>
    </itunes:category>
    <itunes:category text="Technology"/>
    <itunes:type>episodic</itunes:type>
    <itunes:author>Wordfence</itunes:author>
    <itunes:image href="https://img.transistorcdn.com/Wq_-Nf8t4p9FMeTFUnB2VFtU_MTLRjwTzZznjj5L4hs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.jpg"/>
    <itunes:summary>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.</itunes:summary>
    <itunes:subtitle>Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape.</itunes:subtitle>
    <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
    <itunes:owner>
      <itunes:name>Wordfence</itunes:name>
    </itunes:owner>
    <itunes:complete>No</itunes:complete>
    <itunes:explicit>No</itunes:explicit>
    <item>
      <title>OMGF Pro Exploited, Oracle Payments Attack &amp; AI Repo Backdoor | Wordfence Security News #14</title>
      <itunes:episode>14</itunes:episode>
      <podcast:episode>14</podcast:episode>
      <itunes:title>OMGF Pro Exploited, Oracle Payments Attack &amp; AI Repo Backdoor | Wordfence Security News #14</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">2cea1bfa-4578-4608-a02e-6112c4cb1f79</guid>
      <link>https://share.transistor.fm/s/3bea3b6c</link>
      <description>
        <![CDATA[<p><strong>OMGF Pro Exploited, Oracle Payments Attack &amp; AI Repo Backdoor | Wordfence Security News #14</strong></p><p><br></p><p><strong>This week in Wordfence Security News:</strong></p><ul><li>OMGF Pro unauthenticated file upload exploited during disclosure: 60,000+ blocked attempts across nearly 8,000 sites, fixed in 5.2.7</li><li>Oracle E-Business Suite Payments auth bypass exploited in the wild despite a May patch; Shadowserver tracked around 950 exposed EBS instances</li><li>PTC Windchill and FlexPLM unauthenticated RCE added to CISA KEV on June 25 after attackers deployed JSP web shells</li><li>BlueHammer, the deliberately leaked Microsoft Defender flaw, now flagged by CISA as used in ransomware attacks</li><li>SimpleHelp OIDC signature flaw grants fake technician accounts, dropping the Taskweaver loader and Djinn info stealer</li><li>Mozilla 0DIN demo shows a clean GitHub repo tricking Claude Code into fetching a DNS TXT payload and opening a shell</li></ul><p><strong>Timestamps:</strong></p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m48s">0:48</a> Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=3m42s">3:42</a> Oracle E-Business Suite Payments Exploited in the Wild</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=5m21s">5:21</a> PTC Windchill / FlexPLM RCE Added to CISA KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m21s">6:21</a> BlueHammer Microsoft Defender Flaw Used in Ransomware Attacks</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m57s">6:57</a> SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=8m46s">8:46</a> Clean GitHub Repo Tricks AI Coding Agents Into Running Malware</p><p><br></p><p><strong>Story Links:</strong></p><ul><li><a href="https://daan.dev/blog/rants/active-exploit-targeting-omgf-pro/">Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload During Responsible Disclosure Window.</a></li><li><a href="https://www.oracle.com/security-alerts/cspumay2026.html">Oracle E-Business Suite Payments Exploited in the Wild</a></li><li><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">PTC Windchill / FlexPLM RCE Added to CISA KEV</a></li><li><a href="https://www.securityweek.com/bluehammer-vulnerability-exploited-in-ransomware-attacks/">BlueHammer Microsoft Defender Vulnerability Exploited in Ransomware Attacks</a></li><li><a href="https://guides.simple-help.com/kb---security-vulnerabilities-05-2026">SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</a></li><li><a href="https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/">Clean GitHub Repo Tricks AI Coding Agents Into Running Malware / Mozilla 0DIN Claude Code Demo</a></li></ul><p><br></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>OMGF Pro Exploited, Oracle Payments Attack &amp; AI Repo Backdoor | Wordfence Security News #14</strong></p><p><br></p><p><strong>This week in Wordfence Security News:</strong></p><ul><li>OMGF Pro unauthenticated file upload exploited during disclosure: 60,000+ blocked attempts across nearly 8,000 sites, fixed in 5.2.7</li><li>Oracle E-Business Suite Payments auth bypass exploited in the wild despite a May patch; Shadowserver tracked around 950 exposed EBS instances</li><li>PTC Windchill and FlexPLM unauthenticated RCE added to CISA KEV on June 25 after attackers deployed JSP web shells</li><li>BlueHammer, the deliberately leaked Microsoft Defender flaw, now flagged by CISA as used in ransomware attacks</li><li>SimpleHelp OIDC signature flaw grants fake technician accounts, dropping the Taskweaver loader and Djinn info stealer</li><li>Mozilla 0DIN demo shows a clean GitHub repo tricking Claude Code into fetching a DNS TXT payload and opening a shell</li></ul><p><strong>Timestamps:</strong></p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m48s">0:48</a> Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=3m42s">3:42</a> Oracle E-Business Suite Payments Exploited in the Wild</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=5m21s">5:21</a> PTC Windchill / FlexPLM RCE Added to CISA KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m21s">6:21</a> BlueHammer Microsoft Defender Flaw Used in Ransomware Attacks</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m57s">6:57</a> SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=8m46s">8:46</a> Clean GitHub Repo Tricks AI Coding Agents Into Running Malware</p><p><br></p><p><strong>Story Links:</strong></p><ul><li><a href="https://daan.dev/blog/rants/active-exploit-targeting-omgf-pro/">Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload During Responsible Disclosure Window.</a></li><li><a href="https://www.oracle.com/security-alerts/cspumay2026.html">Oracle E-Business Suite Payments Exploited in the Wild</a></li><li><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">PTC Windchill / FlexPLM RCE Added to CISA KEV</a></li><li><a href="https://www.securityweek.com/bluehammer-vulnerability-exploited-in-ransomware-attacks/">BlueHammer Microsoft Defender Vulnerability Exploited in Ransomware Attacks</a></li><li><a href="https://guides.simple-help.com/kb---security-vulnerabilities-05-2026">SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</a></li><li><a href="https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/">Clean GitHub Repo Tricks AI Coding Agents Into Running Malware / Mozilla 0DIN Claude Code Demo</a></li></ul><p><br></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 31 Jul 2026 11:41:02 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/3bea3b6c/9cbacb0b.mp3" length="10598748" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/T9yjBsBH8sypZHsEAnVjNG_wycGu06N_3eOac9ovhlc/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8wMDEw/OGVlYmNiNjdhZWE0/NzZmMmMzNzAxMmY0/NjUwZi5qcGc.jpg"/>
      <itunes:duration>638</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>OMGF Pro Exploited, Oracle Payments Attack &amp; AI Repo Backdoor | Wordfence Security News #14</strong></p><p><br></p><p><strong>This week in Wordfence Security News:</strong></p><ul><li>OMGF Pro unauthenticated file upload exploited during disclosure: 60,000+ blocked attempts across nearly 8,000 sites, fixed in 5.2.7</li><li>Oracle E-Business Suite Payments auth bypass exploited in the wild despite a May patch; Shadowserver tracked around 950 exposed EBS instances</li><li>PTC Windchill and FlexPLM unauthenticated RCE added to CISA KEV on June 25 after attackers deployed JSP web shells</li><li>BlueHammer, the deliberately leaked Microsoft Defender flaw, now flagged by CISA as used in ransomware attacks</li><li>SimpleHelp OIDC signature flaw grants fake technician accounts, dropping the Taskweaver loader and Djinn info stealer</li><li>Mozilla 0DIN demo shows a clean GitHub repo tricking Claude Code into fetching a DNS TXT payload and opening a shell</li></ul><p><strong>Timestamps:</strong></p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=0m48s">0:48</a> Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=3m42s">3:42</a> Oracle E-Business Suite Payments Exploited in the Wild</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=5m21s">5:21</a> PTC Windchill / FlexPLM RCE Added to CISA KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m21s">6:21</a> BlueHammer Microsoft Defender Flaw Used in Ransomware Attacks</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=6m57s">6:57</a> SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=641#t=8m46s">8:46</a> Clean GitHub Repo Tricks AI Coding Agents Into Running Malware</p><p><br></p><p><strong>Story Links:</strong></p><ul><li><a href="https://daan.dev/blog/rants/active-exploit-targeting-omgf-pro/">Active Exploitation of OMGF Pro Unauthenticated Arbitrary File Upload During Responsible Disclosure Window.</a></li><li><a href="https://www.oracle.com/security-alerts/cspumay2026.html">Oracle E-Business Suite Payments Exploited in the Wild</a></li><li><a href="https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability">PTC Windchill / FlexPLM RCE Added to CISA KEV</a></li><li><a href="https://www.securityweek.com/bluehammer-vulnerability-exploited-in-ransomware-attacks/">BlueHammer Microsoft Defender Vulnerability Exploited in Ransomware Attacks</a></li><li><a href="https://guides.simple-help.com/kb---security-vulnerabilities-05-2026">SimpleHelp Auth Bypass Exploited to Deploy Djinn Stealer</a></li><li><a href="https://www.bleepingcomputer.com/news/security/clean-github-repo-tricks-ai-coding-agents-into-running-malware/">Clean GitHub Repo Tricks AI Coding Agents Into Running Malware / Mozilla 0DIN Claude Code Demo</a></li></ul><p><br></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/3bea3b6c/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3bea3b6c/transcript.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3bea3b6c/transcript.json" type="application/json"/>
    </item>
    <item>
      <title>Uncanny Automator Backdoor, Splunk Exploited &amp; AI Key Theft | Wordfence Security News #13</title>
      <itunes:episode>13</itunes:episode>
      <podcast:episode>13</podcast:episode>
      <itunes:title>Uncanny Automator Backdoor, Splunk Exploited &amp; AI Key Theft | Wordfence Security News #13</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">e7de7678-e2e6-44e6-86f5-060401a2394c</guid>
      <link>https://share.transistor.fm/s/a9410e7a</link>
      <description>
        <![CDATA[<p><strong>Uncanny Automator Backdoor, Splunk Exploited &amp; AI Key Theft</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 23, 2026):</p><p>• Uncanny Automator Pro Backdoored Through Update Server<br>• Splunk Enterprise Flaw Exploited in the Wild<br>• Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br>• LiteLLM Flaw Puts AI Gateway Keys at Risk<br>• Malicious JetBrains Plugins Stole AI API Keys</p><p>Timestamps:</p><p><br></p><p><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM">00:00</a> Intro<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=37s">00:37</a> Uncanny Automator Pro Backdoored Through Update Server<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=368s">06:08</a> Splunk Enterprise Flaw Exploited in the Wild<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=534s">08:54</a> Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=709s">11:49</a> LiteLLM Flaw Puts AI Gateway Keys at Risk<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=879s">14:39</a> Malicious JetBrains Plugins Stole AI API Keys</p><p><br></p><p>Story Links:</p><p>1. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFA0UENUU0g0QmRtV0xrb21nYXBrY2FDUnJfZ3xBQ3Jtc0trWTVXR216WmdWVExlVUk3SWpaUU5kY1hrUDQ5Z0JZMGlrbGFSdDE2anhETEZEdnZ1TnpYM1NfT3FXdkNFVENnWFBBU3RnYzJxaXl1RU9wakRfMkZld3ZOUW1CRklJaC1HenZiQXhZcm1GWnBJdS1Scw&amp;q=https%3A%2F%2Fautomatorplugin.com%2Fsecurity-incident-notice-uncanny-automator%2F&amp;v=mTQjEc5pHgM">Uncanny Automator Pro Backdoored Through Update Server</a></p><p>2. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbkl4SUY1UENRNGVESnJSM2hGUTExZmhXck40UXxBQ3Jtc0tsYkVoZHVUdUxZclRzb2lkaWwtb2NPQnFhck8zTmx2MWVCM3U0T25YWnAta3RWSVNkMWFOdjdEbktqdXZnZENERDJha1FqRGhPVGRVSHdvRDlrQTVncEYzS1pybGlIU0JXM0I1LTFRSDNqaTBmNkp2MA&amp;q=https%3A%2F%2Fadvisory.splunk.com%2Fadvisories%2FSVD-2026-0603&amp;v=mTQjEc5pHgM">Splunk Enterprise Flaw Exploited in the Wild</a></p><p>3. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGtlVWJ2d3dESFpFZ3RuTVhPVjc5QVFiMFEwZ3xBQ3Jtc0tueDBUYWQ4R3pRQWFMTlFYcVhYOHZqamZway11QlpySWpEeFkwamNtaFJSbUlRMWtqdEpqWVB1RVhNTUpOekxURHFKbmRaa2EzaFMwbTh2OGZYRnUtZVdMNVBxWS00RGZuNXA5WUQ5ajJMcHlSSlk5bw&amp;q=https%3A%2F%2Ffortiguard.fortinet.com%2Fpsirt%2FFG-IR-26-141&amp;v=mTQjEc5pHgM">Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls</a></p><p>4. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqazIwSkRqenlnd19ucGg3NmVnS3ZWMnhaT0xqQXxBQ3Jtc0trbkxTVmFna19GWllwMi02RjZEdTZUNVkwY1JFYUFtSFJoaU05LWJqT3JVY0kzd1VCMmhjalVyQ3QwWUhIbGpwaGNlVEYtZE1NOERMd1U4bHdLM0R0SlNfaXp1dTRpR0dhN09JYnFVTVd2T2xTTzBaQQ&amp;q=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-v4p8-mg3p-g94g&amp;v=mTQjEc5pHgM">LiteLLM Flaw Puts AI Gateway Keys at Risk</a></p><p>5. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbXNwUGg1NVFaeUtrWTIzZWxETkZsSVU5Tl8wUXxBQ3Jtc0tuME9ERVNSR3Zaa3BLUW1RN3JqdmVjcWxMa3BlOU9vbVkwZ19PRm4wV1dUckk2ZjV0U3FhZkxJb2NjZ3A1V1pJNFVTZWpXMFV4RUMzZ3hMY0xpX3ZoM2hVQld1ek92bGlQSmdVT1dGYXFjTHBMZEZBWQ&amp;q=https%3A%2F%2Fblog.jetbrains.com%2Fplatform%2F2026%2F06%2Fmarketplace-ecosystem-security-update-malicious-ai-plugins%2F&amp;v=mTQjEc5pHgM">Malicious JetBrains Plugins Stole AI API Keys</a></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Uncanny Automator Backdoor, Splunk Exploited &amp; AI Key Theft</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 23, 2026):</p><p>• Uncanny Automator Pro Backdoored Through Update Server<br>• Splunk Enterprise Flaw Exploited in the Wild<br>• Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br>• LiteLLM Flaw Puts AI Gateway Keys at Risk<br>• Malicious JetBrains Plugins Stole AI API Keys</p><p>Timestamps:</p><p><br></p><p><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM">00:00</a> Intro<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=37s">00:37</a> Uncanny Automator Pro Backdoored Through Update Server<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=368s">06:08</a> Splunk Enterprise Flaw Exploited in the Wild<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=534s">08:54</a> Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=709s">11:49</a> LiteLLM Flaw Puts AI Gateway Keys at Risk<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=879s">14:39</a> Malicious JetBrains Plugins Stole AI API Keys</p><p><br></p><p>Story Links:</p><p>1. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFA0UENUU0g0QmRtV0xrb21nYXBrY2FDUnJfZ3xBQ3Jtc0trWTVXR216WmdWVExlVUk3SWpaUU5kY1hrUDQ5Z0JZMGlrbGFSdDE2anhETEZEdnZ1TnpYM1NfT3FXdkNFVENnWFBBU3RnYzJxaXl1RU9wakRfMkZld3ZOUW1CRklJaC1HenZiQXhZcm1GWnBJdS1Scw&amp;q=https%3A%2F%2Fautomatorplugin.com%2Fsecurity-incident-notice-uncanny-automator%2F&amp;v=mTQjEc5pHgM">Uncanny Automator Pro Backdoored Through Update Server</a></p><p>2. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbkl4SUY1UENRNGVESnJSM2hGUTExZmhXck40UXxBQ3Jtc0tsYkVoZHVUdUxZclRzb2lkaWwtb2NPQnFhck8zTmx2MWVCM3U0T25YWnAta3RWSVNkMWFOdjdEbktqdXZnZENERDJha1FqRGhPVGRVSHdvRDlrQTVncEYzS1pybGlIU0JXM0I1LTFRSDNqaTBmNkp2MA&amp;q=https%3A%2F%2Fadvisory.splunk.com%2Fadvisories%2FSVD-2026-0603&amp;v=mTQjEc5pHgM">Splunk Enterprise Flaw Exploited in the Wild</a></p><p>3. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGtlVWJ2d3dESFpFZ3RuTVhPVjc5QVFiMFEwZ3xBQ3Jtc0tueDBUYWQ4R3pRQWFMTlFYcVhYOHZqamZway11QlpySWpEeFkwamNtaFJSbUlRMWtqdEpqWVB1RVhNTUpOekxURHFKbmRaa2EzaFMwbTh2OGZYRnUtZVdMNVBxWS00RGZuNXA5WUQ5ajJMcHlSSlk5bw&amp;q=https%3A%2F%2Ffortiguard.fortinet.com%2Fpsirt%2FFG-IR-26-141&amp;v=mTQjEc5pHgM">Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls</a></p><p>4. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqazIwSkRqenlnd19ucGg3NmVnS3ZWMnhaT0xqQXxBQ3Jtc0trbkxTVmFna19GWllwMi02RjZEdTZUNVkwY1JFYUFtSFJoaU05LWJqT3JVY0kzd1VCMmhjalVyQ3QwWUhIbGpwaGNlVEYtZE1NOERMd1U4bHdLM0R0SlNfaXp1dTRpR0dhN09JYnFVTVd2T2xTTzBaQQ&amp;q=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-v4p8-mg3p-g94g&amp;v=mTQjEc5pHgM">LiteLLM Flaw Puts AI Gateway Keys at Risk</a></p><p>5. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbXNwUGg1NVFaeUtrWTIzZWxETkZsSVU5Tl8wUXxBQ3Jtc0tuME9ERVNSR3Zaa3BLUW1RN3JqdmVjcWxMa3BlOU9vbVkwZ19PRm4wV1dUckk2ZjV0U3FhZkxJb2NjZ3A1V1pJNFVTZWpXMFV4RUMzZ3hMY0xpX3ZoM2hVQld1ek92bGlQSmdVT1dGYXFjTHBMZEZBWQ&amp;q=https%3A%2F%2Fblog.jetbrains.com%2Fplatform%2F2026%2F06%2Fmarketplace-ecosystem-security-update-malicious-ai-plugins%2F&amp;v=mTQjEc5pHgM">Malicious JetBrains Plugins Stole AI API Keys</a></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 09 Jul 2026 11:37:30 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/a9410e7a/cd66d774.mp3" length="17396837" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/LQ7uVY7670qe1IQpsr8FScpI8HGsywj50LdlY3R2NME/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mZjYz/ZjM4MjExZGY4NTBk/MTZlNjM4MTkyMzI3/OTA3NC5qcGc.jpg"/>
      <itunes:duration>1085</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Uncanny Automator Backdoor, Splunk Exploited &amp; AI Key Theft</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 23, 2026):</p><p>• Uncanny Automator Pro Backdoored Through Update Server<br>• Splunk Enterprise Flaw Exploited in the Wild<br>• Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br>• LiteLLM Flaw Puts AI Gateway Keys at Risk<br>• Malicious JetBrains Plugins Stole AI API Keys</p><p>Timestamps:</p><p><br></p><p><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM">00:00</a> Intro<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=37s">00:37</a> Uncanny Automator Pro Backdoored Through Update Server<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=368s">06:08</a> Splunk Enterprise Flaw Exploited in the Wild<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=534s">08:54</a> Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=709s">11:49</a> LiteLLM Flaw Puts AI Gateway Keys at Risk<br><a href="https://www.youtube.com/watch?v=mTQjEc5pHgM&amp;t=879s">14:39</a> Malicious JetBrains Plugins Stole AI API Keys</p><p><br></p><p>Story Links:</p><p>1. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbFA0UENUU0g0QmRtV0xrb21nYXBrY2FDUnJfZ3xBQ3Jtc0trWTVXR216WmdWVExlVUk3SWpaUU5kY1hrUDQ5Z0JZMGlrbGFSdDE2anhETEZEdnZ1TnpYM1NfT3FXdkNFVENnWFBBU3RnYzJxaXl1RU9wakRfMkZld3ZOUW1CRklJaC1HenZiQXhZcm1GWnBJdS1Scw&amp;q=https%3A%2F%2Fautomatorplugin.com%2Fsecurity-incident-notice-uncanny-automator%2F&amp;v=mTQjEc5pHgM">Uncanny Automator Pro Backdoored Through Update Server</a></p><p>2. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbkl4SUY1UENRNGVESnJSM2hGUTExZmhXck40UXxBQ3Jtc0tsYkVoZHVUdUxZclRzb2lkaWwtb2NPQnFhck8zTmx2MWVCM3U0T25YWnAta3RWSVNkMWFOdjdEbktqdXZnZENERDJha1FqRGhPVGRVSHdvRDlrQTVncEYzS1pybGlIU0JXM0I1LTFRSDNqaTBmNkp2MA&amp;q=https%3A%2F%2Fadvisory.splunk.com%2Fadvisories%2FSVD-2026-0603&amp;v=mTQjEc5pHgM">Splunk Enterprise Flaw Exploited in the Wild</a></p><p>3. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbGtlVWJ2d3dESFpFZ3RuTVhPVjc5QVFiMFEwZ3xBQ3Jtc0tueDBUYWQ4R3pRQWFMTlFYcVhYOHZqamZway11QlpySWpEeFkwamNtaFJSbUlRMWtqdEpqWVB1RVhNTUpOekxURHFKbmRaa2EzaFMwbTh2OGZYRnUtZVdMNVBxWS00RGZuNXA5WUQ5ajJMcHlSSlk5bw&amp;q=https%3A%2F%2Ffortiguard.fortinet.com%2Fpsirt%2FFG-IR-26-141&amp;v=mTQjEc5pHgM">Fortinet Sandbox Flaws Targeted as FortiBleed Hits Firewalls</a></p><p>4. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqazIwSkRqenlnd19ucGg3NmVnS3ZWMnhaT0xqQXxBQ3Jtc0trbkxTVmFna19GWllwMi02RjZEdTZUNVkwY1JFYUFtSFJoaU05LWJqT3JVY0kzd1VCMmhjalVyQ3QwWUhIbGpwaGNlVEYtZE1NOERMd1U4bHdLM0R0SlNfaXp1dTRpR0dhN09JYnFVTVd2T2xTTzBaQQ&amp;q=https%3A%2F%2Fgithub.com%2Fadvisories%2FGHSA-v4p8-mg3p-g94g&amp;v=mTQjEc5pHgM">LiteLLM Flaw Puts AI Gateway Keys at Risk</a></p><p>5. <a href="https://www.youtube.com/redirect?event=video_description&amp;redir_token=QUFFLUhqbXNwUGg1NVFaeUtrWTIzZWxETkZsSVU5Tl8wUXxBQ3Jtc0tuME9ERVNSR3Zaa3BLUW1RN3JqdmVjcWxMa3BlOU9vbVkwZ19PRm4wV1dUckk2ZjV0U3FhZkxJb2NjZ3A1V1pJNFVTZWpXMFV4RUMzZ3hMY0xpX3ZoM2hVQld1ek92bGlQSmdVT1dGYXFjTHBMZEZBWQ&amp;q=https%3A%2F%2Fblog.jetbrains.com%2Fplatform%2F2026%2F06%2Fmarketplace-ecosystem-security-update-malicious-ai-plugins%2F&amp;v=mTQjEc5pHgM">Malicious JetBrains Plugins Stole AI API Keys</a></p><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/a9410e7a/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/a9410e7a/transcript.txt" type="text/plain"/>
    </item>
    <item>
      <title>WordPress Plugin Supply Chain Attacks, Ivanti CVSS 10 &amp; phpBB Hijacks | Wordfence Security News #12</title>
      <itunes:episode>12</itunes:episode>
      <podcast:episode>12</podcast:episode>
      <itunes:title>WordPress Plugin Supply Chain Attacks, Ivanti CVSS 10 &amp; phpBB Hijacks | Wordfence Security News #12</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">8e28d6b2-c43d-4598-8ebe-b88c88a42c49</guid>
      <link>https://share.transistor.fm/s/8d38efd5</link>
      <description>
        <![CDATA[<p><strong>WordPress Supply Chain Attacks, Ivanti Root Flaw, and phpBB Account Takeovers</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 15, 2026):</p><ul><li>ShapedPlugin's paid pro plugins were backdoored via the vendor's update system, stealing passwords and 2FA secrets</li><li>OptinMonster, TrustPulse, and PushEngage served a tampered CDN script that targeted logged-in admins</li><li>Oracle PeopleSoft zero-day exploited by ShinyHunters hit 300+ systems, 68% in higher education</li><li>Ivanti Sentry CVSS 10 OS command injection flaw gives attackers root, added to CISA KEV</li><li>Langflow AI app builder path traversal flaw now actively exploited against unpatched instances</li><li>phpBB authentication bypass lets attackers hijack any account with just a username and one request</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m42s">0:42</a> ShapedPlugin Multiple Plugins Supply Chain Compromised</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=5m11s">5:11</a> OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=7m48s">7:48</a> Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=10m17s">10:17</a> Ivanti Sentry CVSS 10 RCE Added to KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=11m53s">11:53</a> Langflow RCE Actively Exploited Against Exposed AI App Builders</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=13m46s">13:46</a> phpBB Authentication Bypass Lets Attackers Hijack Accounts</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/detail/product-slider-pro-for-woocommerce-354-backdoored-software">ShapedPlugin Multiple Plugins Supply Chain Compromised</a></li><li><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35273">Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10520">Ivanti Sentry CVSS 10 RCE Added to KEV</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5027">Langflow RCE Actively Exploited Against Exposed AI App Builders</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48611">phpBB Authentication Bypass Lets Attackers Hijack Accounts</a></li></ul><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>WordPress Supply Chain Attacks, Ivanti Root Flaw, and phpBB Account Takeovers</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 15, 2026):</p><ul><li>ShapedPlugin's paid pro plugins were backdoored via the vendor's update system, stealing passwords and 2FA secrets</li><li>OptinMonster, TrustPulse, and PushEngage served a tampered CDN script that targeted logged-in admins</li><li>Oracle PeopleSoft zero-day exploited by ShinyHunters hit 300+ systems, 68% in higher education</li><li>Ivanti Sentry CVSS 10 OS command injection flaw gives attackers root, added to CISA KEV</li><li>Langflow AI app builder path traversal flaw now actively exploited against unpatched instances</li><li>phpBB authentication bypass lets attackers hijack any account with just a username and one request</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m42s">0:42</a> ShapedPlugin Multiple Plugins Supply Chain Compromised</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=5m11s">5:11</a> OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=7m48s">7:48</a> Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=10m17s">10:17</a> Ivanti Sentry CVSS 10 RCE Added to KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=11m53s">11:53</a> Langflow RCE Actively Exploited Against Exposed AI App Builders</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=13m46s">13:46</a> phpBB Authentication Bypass Lets Attackers Hijack Accounts</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/detail/product-slider-pro-for-woocommerce-354-backdoored-software">ShapedPlugin Multiple Plugins Supply Chain Compromised</a></li><li><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35273">Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10520">Ivanti Sentry CVSS 10 RCE Added to KEV</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5027">Langflow RCE Actively Exploited Against Exposed AI App Builders</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48611">phpBB Authentication Bypass Lets Attackers Hijack Accounts</a></li></ul><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 26 Jun 2026 12:13:26 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/8d38efd5/4d97cf74.mp3" length="15430820" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/ID-T8M5QX2pqmkBmdCkBOUycLIoGUPH81QSCHagzpTw/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zNGFh/OWNlOWUyOWJiOTVl/MGU0NTU2ZDMyM2Qy/NDlhMy5qcGc.jpg"/>
      <itunes:duration>931</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>WordPress Supply Chain Attacks, Ivanti Root Flaw, and phpBB Account Takeovers</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 15, 2026):</p><ul><li>ShapedPlugin's paid pro plugins were backdoored via the vendor's update system, stealing passwords and 2FA secrets</li><li>OptinMonster, TrustPulse, and PushEngage served a tampered CDN script that targeted logged-in admins</li><li>Oracle PeopleSoft zero-day exploited by ShinyHunters hit 300+ systems, 68% in higher education</li><li>Ivanti Sentry CVSS 10 OS command injection flaw gives attackers root, added to CISA KEV</li><li>Langflow AI app builder path traversal flaw now actively exploited against unpatched instances</li><li>phpBB authentication bypass lets attackers hijack any account with just a username and one request</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=0m42s">0:42</a> ShapedPlugin Multiple Plugins Supply Chain Compromised</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=5m11s">5:11</a> OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=7m48s">7:48</a> Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=10m17s">10:17</a> Ivanti Sentry CVSS 10 RCE Added to KEV</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=11m53s">11:53</a> Langflow RCE Actively Exploited Against Exposed AI App Builders</p><p><a href="http://127.0.0.1:5360/video/podcast-checklist?id=592#t=13m46s">13:46</a> phpBB Authentication Bypass Lets Attackers Hijack Accounts</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/detail/product-slider-pro-for-woocommerce-354-backdoored-software">ShapedPlugin Multiple Plugins Supply Chain Compromised</a></li><li><a href="https://sansec.io/research/optinmonster-supply-chain-attack">OptinMonster / TrustPulse / PushEngage Tampered Script Served via Compromised CDN</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35273">Oracle PeopleSoft Zero-Day Exploited by ShinyHunters</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10520">Ivanti Sentry CVSS 10 RCE Added to KEV</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5027">Langflow RCE Actively Exploited Against Exposed AI App Builders</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48611">phpBB Authentication Bypass Lets Attackers Hijack Accounts</a></li></ul><p>Stay informed and secure: get the latest Wordfence Security News on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/8d38efd5/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>Kirki &amp; UpdraftPlus Exploits, Miasma Supply Chain Worm &amp; 3 Zero-Days | Wordfence Security News #11</title>
      <itunes:episode>11</itunes:episode>
      <podcast:episode>11</podcast:episode>
      <itunes:title>Kirki &amp; UpdraftPlus Exploits, Miasma Supply Chain Worm &amp; 3 Zero-Days | Wordfence Security News #11</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">37e6a9ae-e910-407d-bea2-db33f83fd554</guid>
      <link>https://share.transistor.fm/s/78440e32</link>
      <description>
        <![CDATA[<p><strong>Kirki &amp; UpdraftPlus Exploited, Miasma Supply Chain Worm &amp; 3 Zero-Days | Wordfence Security News #11</strong></p><p><br></p><p>In this episode of Wordfence Security News:</p><ul><li>Kirki's password reset endpoint lets unauthenticated attackers redirect admin reset links to any inbox, enabling full account takeover.</li><li>UpdraftPlus UpdraftCentral auth bypass allows unauthenticated attackers to install plugins and achieve remote code execution on connected sites.</li><li>Check Point Remote Access VPN zero-day exploited since May 7 lets attackers bypass credentials entirely; one intrusion tied to Qilin ransomware affiliate.</li><li>Cisco Catalyst SD-WAN Manager zero-day command injection, chainable with two auth bypasses, lets attackers push rogue config to all edge devices as root.</li><li>Chrome 149 patches 429 vulnerabilities - nearly triple the previous record - including 22 critical CVEs, with $208,000 in bounty rewards paid out.</li><li>Miasma supply chain worm hit 113+ GitHub repositories by planting AI coding tool config files that exfiltrate cloud credentials on folder open.</li></ul><p><br></p><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m39s">0:39</a> Kirki Password Reset Exploit Goes Live</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=2m59s">2:59</a> UpdraftPlus UpdraftCentral Auth Bypass to RCE</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=6m50s">6:50</a> Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=8m59s">8:59</a> Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=11m20s">11:20</a> Chrome 149 Ships Record Browser Security Update</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=13m20s">13:20</a> Miasma Worm Targets Developer Workflows and AI Coding Tools</p><p><br></p><p>Story Links:</p><p><br></p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799">Kirki Password Reset Exploit Goes Live</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f">UpdraftPlus UpdraftCentral Auth Bypass to RCE</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751">Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</a></li><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</a></li><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html">Chrome 149 Ships Record Browser Security Update</a></li><li><a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents">Miasma Worm Targets Developer Workflows and AI Coding Tools</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Kirki &amp; UpdraftPlus Exploited, Miasma Supply Chain Worm &amp; 3 Zero-Days | Wordfence Security News #11</strong></p><p><br></p><p>In this episode of Wordfence Security News:</p><ul><li>Kirki's password reset endpoint lets unauthenticated attackers redirect admin reset links to any inbox, enabling full account takeover.</li><li>UpdraftPlus UpdraftCentral auth bypass allows unauthenticated attackers to install plugins and achieve remote code execution on connected sites.</li><li>Check Point Remote Access VPN zero-day exploited since May 7 lets attackers bypass credentials entirely; one intrusion tied to Qilin ransomware affiliate.</li><li>Cisco Catalyst SD-WAN Manager zero-day command injection, chainable with two auth bypasses, lets attackers push rogue config to all edge devices as root.</li><li>Chrome 149 patches 429 vulnerabilities - nearly triple the previous record - including 22 critical CVEs, with $208,000 in bounty rewards paid out.</li><li>Miasma supply chain worm hit 113+ GitHub repositories by planting AI coding tool config files that exfiltrate cloud credentials on folder open.</li></ul><p><br></p><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m39s">0:39</a> Kirki Password Reset Exploit Goes Live</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=2m59s">2:59</a> UpdraftPlus UpdraftCentral Auth Bypass to RCE</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=6m50s">6:50</a> Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=8m59s">8:59</a> Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=11m20s">11:20</a> Chrome 149 Ships Record Browser Security Update</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=13m20s">13:20</a> Miasma Worm Targets Developer Workflows and AI Coding Tools</p><p><br></p><p>Story Links:</p><p><br></p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799">Kirki Password Reset Exploit Goes Live</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f">UpdraftPlus UpdraftCentral Auth Bypass to RCE</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751">Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</a></li><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</a></li><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html">Chrome 149 Ships Record Browser Security Update</a></li><li><a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents">Miasma Worm Targets Developer Workflows and AI Coding Tools</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 18 Jun 2026 12:45:58 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/78440e32/d0dcda18.mp3" length="15768215" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/rhjGlzmiMAknZiMzJ4LKA-tAFqKQXbb6Eo_U6l4kj8o/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9lNjZh/YWNhMzAxZGU2N2Qy/ODM2ZDVjNjJkZTkz/ZDMxMS5qcGc.jpg"/>
      <itunes:duration>972</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Kirki &amp; UpdraftPlus Exploited, Miasma Supply Chain Worm &amp; 3 Zero-Days | Wordfence Security News #11</strong></p><p><br></p><p>In this episode of Wordfence Security News:</p><ul><li>Kirki's password reset endpoint lets unauthenticated attackers redirect admin reset links to any inbox, enabling full account takeover.</li><li>UpdraftPlus UpdraftCentral auth bypass allows unauthenticated attackers to install plugins and achieve remote code execution on connected sites.</li><li>Check Point Remote Access VPN zero-day exploited since May 7 lets attackers bypass credentials entirely; one intrusion tied to Qilin ransomware affiliate.</li><li>Cisco Catalyst SD-WAN Manager zero-day command injection, chainable with two auth bypasses, lets attackers push rogue config to all edge devices as root.</li><li>Chrome 149 patches 429 vulnerabilities - nearly triple the previous record - including 22 critical CVEs, with $208,000 in bounty rewards paid out.</li><li>Miasma supply chain worm hit 113+ GitHub repositories by planting AI coding tool config files that exfiltrate cloud credentials on folder open.</li></ul><p><br></p><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=0m39s">0:39</a> Kirki Password Reset Exploit Goes Live</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=2m59s">2:59</a> UpdraftPlus UpdraftCentral Auth Bypass to RCE</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=6m50s">6:50</a> Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=8m59s">8:59</a> Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=11m20s">11:20</a> Chrome 149 Ships Record Browser Security Update</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=575#t=13m20s">13:20</a> Miasma Worm Targets Developer Workflows and AI Coding Tools</p><p><br></p><p>Story Links:</p><p><br></p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/3b5630bd-5bce-4226-959f-5e81ae69b799">Kirki Password Reset Exploit Goes Live</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e901c2a0-2477-4b9a-8483-6002419e0a2f">UpdraftPlus UpdraftCentral Auth Bypass to RCE</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50751">Check Point VPN Zero-Day Exploited by Qilin Ransomware Affiliate</a></li><li><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx">Cisco SD-WAN Manager Zero-Day Exploited to Gain Root</a></li><li><a href="https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html">Chrome 149 Ships Record Browser Security Update</a></li><li><a href="https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents">Miasma Worm Targets Developer Workflows and AI Coding Tools</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/78440e32/transcript.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/78440e32/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/78440e32/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion</title>
      <itunes:episode>10</itunes:episode>
      <podcast:episode>10</podcast:episode>
      <itunes:title>Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bd77db7c-0f5e-4d42-b565-a169a985efc5</guid>
      <link>https://share.transistor.fm/s/451a2ae5</link>
      <description>
        <![CDATA[<p><strong>Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 1, 2026):</p><ul><li>WP Maps Pro flaw lets unauthenticated attackers forge admin accounts; exploitation began May 19th, before public disclosure.</li><li>Palo Alto PAN-OS GlobalProtect authentication bypass under active attack; CISA added it to KEV with a June 1st federal patch deadline.</li><li>FortiClient EMS exploited post-patch to push EKZ infostealer disguised as a Fortinet update to managed endpoints.</li><li>Sysdig documented the first captured intrusion where an LLM agent drove post-compromise activity in real time via unpatched Marimo.</li><li>Flowise one-click RCE lets a malicious chatflow execute code on import; self-hosted installs at risk via STDIO MCP execution path.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m34s">0:34</a> WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=3m0s">3:00</a> Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=5m36s">5:36</a> FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=7m11s">7:11</a> First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=9m32s">9:32</a> Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-gold/wp-maps-pro-610-unauthenticated-privilege-escalation-via-administrator-account-creation-to-wpgmp-temp-access-ajax-ajax-action">WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</a></li><li><a href="https://security.paloaltonetworks.com/CVE-2026-0257">Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</a></li><li><a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/">FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</a></li><li><a href="https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots">First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</a></li><li><a href="https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability">Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 1, 2026):</p><ul><li>WP Maps Pro flaw lets unauthenticated attackers forge admin accounts; exploitation began May 19th, before public disclosure.</li><li>Palo Alto PAN-OS GlobalProtect authentication bypass under active attack; CISA added it to KEV with a June 1st federal patch deadline.</li><li>FortiClient EMS exploited post-patch to push EKZ infostealer disguised as a Fortinet update to managed endpoints.</li><li>Sysdig documented the first captured intrusion where an LLM agent drove post-compromise activity in real time via unpatched Marimo.</li><li>Flowise one-click RCE lets a malicious chatflow execute code on import; self-hosted installs at risk via STDIO MCP execution path.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m34s">0:34</a> WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=3m0s">3:00</a> Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=5m36s">5:36</a> FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=7m11s">7:11</a> First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=9m32s">9:32</a> Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-gold/wp-maps-pro-610-unauthenticated-privilege-escalation-via-administrator-account-creation-to-wpgmp-temp-access-ajax-ajax-action">WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</a></li><li><a href="https://security.paloaltonetworks.com/CVE-2026-0257">Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</a></li><li><a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/">FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</a></li><li><a href="https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots">First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</a></li><li><a href="https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability">Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Wed, 10 Jun 2026 14:22:31 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/451a2ae5/9c4c7574.mp3" length="11600462" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/_dyTrAkDeCiNe6k5_8ltplDLXgSZZThAH5OC-Nvybws/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yOGVl/OTA5ZjViZmZlNGRj/ZWY2MzY4NTVkMmVi/ZTZjYi5qcGc.jpg"/>
      <itunes:duration>711</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>Wordfence Security News #10 - WPMaps Pro Exploited, Palo Alto VPN Bug, and AI Agent-Driven Intrusion</strong></p><p><br></p><p>This week in Wordfence Security News (Week of June 1, 2026):</p><ul><li>WP Maps Pro flaw lets unauthenticated attackers forge admin accounts; exploitation began May 19th, before public disclosure.</li><li>Palo Alto PAN-OS GlobalProtect authentication bypass under active attack; CISA added it to KEV with a June 1st federal patch deadline.</li><li>FortiClient EMS exploited post-patch to push EKZ infostealer disguised as a Fortinet update to managed endpoints.</li><li>Sysdig documented the first captured intrusion where an LLM agent drove post-compromise activity in real time via unpatched Marimo.</li><li>Flowise one-click RCE lets a malicious chatflow execute code on import; self-hosted installs at risk via STDIO MCP execution path.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=0m34s">0:34</a> WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=3m0s">3:00</a> Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=5m36s">5:36</a> FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=7m11s">7:11</a> First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=574#t=9m32s">9:32</a> Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/wp-google-map-gold/wp-maps-pro-610-unauthenticated-privilege-escalation-via-administrator-account-creation-to-wpgmp-temp-access-ajax-ajax-action">WP Maps Pro Unauthenticated Admin Account Creation (CVE-2026-8732)</a></li><li><a href="https://security.paloaltonetworks.com/CVE-2026-0257">Palo Alto PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257)</a></li><li><a href="https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/">FortiClient EMS Exploited to Deliver EKZ Infostealer (CVE-2026-35616)</a></li><li><a href="https://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots">First Documented LLM-Agent-Driven Intrusion (Marimo, CVE-2026-39987)</a></li><li><a href="https://www.obsidiansecurity.com/blog/when-is-stdio-mcp-actually-a-vulnerability">Flowise One-Click RCE and the MCP stdio Execution Problem (CVE-2026-40933)</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/451a2ae5/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>WooCommerce RCE | Drupal SQLi | Ghost CMS Clickfix Attack | Wordfence Security News | May 25, 2026</title>
      <itunes:episode>9</itunes:episode>
      <podcast:episode>9</podcast:episode>
      <itunes:title>WooCommerce RCE | Drupal SQLi | Ghost CMS Clickfix Attack | Wordfence Security News | May 25, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">70825793-5d79-490f-a827-c27f32296fd1</guid>
      <link>https://share.transistor.fm/s/08da5955</link>
      <description>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Thu, 04 Jun 2026 11:48:05 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/08da5955/20fe2026.mp3" length="32996138" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/UI7kcPE5qRmnipoU1z5frBy0E20sW5VgSRPA2DNqWq0/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS84M2Q3/MDQ2MzE0ODFkZmFk/YWNlOGRiN2ZlZGJk/NDljMy5qcGc.jpg"/>
      <itunes:duration>816</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>WooCommerce RCE active exploitation, Drupal SQL injection attacks, Microsoft Defender zero-days, Ghost CMS ClickFix campaign, TrapDoor supply chain, Nimbus Manticore backdoor.</strong></p><p><br></p><p>This week in Wordfence Security News (Week of May 25, 2025):</p><p><br></p><ul><li>WooCommerce Custom Product Add-ons Pro RCE flaw (CVE-2026-4001) is under active attack, with exploit attempts spiking May 23-27 against the 21,000-install plugin.</li><li>Drupal Core SQL injection (CVE-2026-9082) hit 6,000 sites across 65 countries within 48 hours of patch release, with attackers exploiting PostgreSQL-backend installs.</li><li>Microsoft issued emergency out-of-band Defender patches for two exploited zero-days - RedSun and UnDefend - after a researcher published proof-of-concept exploits without coordinated disclosure.</li><li>Over 700 Ghost CMS sites were compromised via a ClickFix campaign exploiting a SQL injection flaw discovered by Claude Opus 4.6 during Anthropic security testing.</li><li>TrapDoor cross-ecosystem supply chain campaign spread across NPM, PyPI, and Crates.io with 34-plus malicious packages stealing SSH keys, cloud credentials, and crypto wallet data.</li><li>Iranian state-aligned Nimbus Manticore ran three campaign waves since late February, deploying a new AI-assisted MiniFast backdoor via phishing, trojanized Zoom installers, and search engine poisoning.</li></ul><p>Timestamps:</p><p><br></p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m0s">0:00</a> Introduction</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=0m31s">0:31</a> WooCommerce Custom Product Add-ons Pro RCE Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=2m6s">2:06</a> Drupal Core SQL Injection Active Exploitation</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=4m37s">4:37</a> Microsoft Defender RedSun and UnDefend Zero-Days</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=7m11s">7:11</a> Ghost CMS ClickFix Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=9m43s">9:43</a> TrapDoor Cross-Ecosystem Supply Chain Campaign</p><p><a href="http://127.0.0.1:5252/video/podcast-checklist?id=561#t=11m43s">11:43</a> Nimbus Manticore AI-Assisted MiniFast Backdoor</p><p><br></p><p>Story Links:</p><ul><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/woo-custom-product-addons-pro/woocommerce-custom-product-addons-pro-541-unauthenticated-remote-code-execution-via-custom-pricing-formula">WooCommerce Custom Product Addons Pro RCE (CVE-2026-4001)</a></li><li><a href="https://www.drupal.org/sa-core-2026-004">Drupal Core SQL Injection (CVE-2026-9082)</a></li><li><a href="https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/">Microsoft Defender RedSun and UnDefend Zero-Days (CVE-2026-41091, CVE-2026-45498)</a></li><li><a href="https://github.com/advisories/GHSA-w52v-v783-gw97">Ghost CMS ClickFix Campaign (CVE-2026-26980)</a></li><li><a href="https://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates">TrapDoor Cross-Ecosystem Supply Chain Campaign</a></li><li><a href="https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/">Nimbus Manticore AI-Assisted MiniFast Backdoor</a></li></ul><p><br></p><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Cybersecurity, WooCommerce, Drupal, Ghost CMS, Clickfix, WordPress, Wordfence Security News</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/08da5955/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026</title>
      <itunes:episode>8</itunes:episode>
      <podcast:episode>8</podcast:episode>
      <itunes:title>Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">1aa0cca5-dceb-4885-8986-74ef1f6ce4d4</guid>
      <link>https://share.transistor.fm/s/3a70d52d</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 22 May 2026 12:12:52 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/3a70d52d/75eabbe8.mp3" length="11548327" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/QU5gKsSkHuHvX_f6qPkLvD0Lxl6r_jBYmB9f78KqdEg/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8xOWYw/OGMxNWI0Yjg4ZjJh/MDQ4MGYxYzkzNzU4/ZDk2ZS5qcGc.jpg"/>
      <itunes:duration>700</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 18, 2026):</strong></p><ul><li>Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.</li><li>Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.</li><li>Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.</li><li>ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.</li><li>Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.</li><li>node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.</li></ul><p><strong>Timestamps:<br></strong><br></p><p>0:00 Introduction<br>0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites<br>2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation<br>5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack<br>7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover<br>9:24 Shai-Hulud Worm Source Code Released on GitHub<br>11:02 node-ipc npm Package Compromised via Expired Maintainer Domain</p><p><br><strong>Story Links:</strong></p><ul><li><strong>Burst Statistics Auth Bypass Threatens 200K WordPress Sites:</strong> <a href="https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/">https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/</a></li><li><strong>Microsoft Exchange OWA Zero-Day Under Active Exploitation:</strong> <a href="https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498">https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498</a></li><li><strong>Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</a></li><li><strong>ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover:</strong> <a href="https://www.hiddenlayer.com/research/chromatoast-served-pre-auth">https://www.hiddenlayer.com/research/chromatoast-served-pre-auth</a></li><li><strong>Shai-Hulud Worm Source Code Released on GitHub:</strong> <a href="https://www.ox.security/blog/shai-hulud-open-source-malware-github/">https://www.ox.security/blog/shai-hulud-open-source-malware-github/</a></li><li><strong>node-ipc npm Package Compromised via Expired Maintainer Domain:</strong> <a href="https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/">https://www.bleepingcomputer.com/news/security/popular-node-ipc-npm-package-compromised-to-steal-credentials/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3a70d52d/transcript.json" type="application/json"/>
    </item>
    <item>
      <title>Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026</title>
      <itunes:episode>7</itunes:episode>
      <podcast:episode>7</podcast:episode>
      <itunes:title>Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">14357644-5dad-4ca6-becb-94c4b91ddfc8</guid>
      <link>https://share.transistor.fm/s/55ee78c9</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 15 May 2026 17:13:28 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/55ee78c9/84d834cf.mp3" length="14653757" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/F_SxDuy1GIS5r5SUnpx68iLA1x_TZghpRX59g9-rUKY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8zZjVj/ZTIyYjYzY2ZiMTBj/NTFiYzg0MWZkMTJl/OTY2NS5wbmc.jpg"/>
      <itunes:duration>608</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of May 11, 2026):</strong></p><ul><li>Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sites</li><li>A critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared host</li><li>Suspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failover</li><li>The Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestations</li><li>Google's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration tool</li><li>A Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH access</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:33 Gravity SMTP Information Disclosure Exploitation<br>3:19 cPanel and WHM Authentication Bypass<br>4:22 Palo Alto PAN-OS Zero-Day<br>5:56 Shai-Hulud Supply Chain Worm Hits TanStack<br>7:09 Google Identifies First AI-Assisted Zero-Day<br>8:24 Dirty Frag Linux Kernel Privilege Escalation</p><p><strong>Story Links:</strong></p><ul><li><strong>Gravity SMTP Exploited at Scale:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-api</a></li><li><strong>PAN-OS zero-day:</strong> <a href="https://security.paloaltonetworks.com/CVE-2026-0300">https://security.paloaltonetworks.com/CVE-2026-0300</a></li><li><strong>Mini Shai-Hulud worm:</strong> <a href="https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised">https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised</a></li><li><strong>Google GTIG AI zero-day:</strong> <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access</a></li><li><strong>DirtyFrag Linux LPE:</strong> <a href="https://github.com/V4bel/dirtyfrag">https://github.com/V4bel/dirtyfrag</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/55ee78c9/transcript.json" type="application/json"/>
    </item>
    <item>
      <title>Breeze Cache Mass Exploitation in 24 Hours | Bitwarden CLI Supply Chain Attack | ADT Confirmed in ShinyHunters Breach | Pack2TheRoot 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651) | Wordfence Security News | Week of April 27, 2026</title>
      <itunes:episode>6</itunes:episode>
      <podcast:episode>6</podcast:episode>
      <itunes:title>Breeze Cache Mass Exploitation in 24 Hours | Bitwarden CLI Supply Chain Attack | ADT Confirmed in ShinyHunters Breach | Pack2TheRoot 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651) | Wordfence Security News | Week of April 27, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">bfe2b51b-9a74-43df-9c57-44587cffae87</guid>
      <link>https://share.transistor.fm/s/84b1ca75</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Mon, 04 May 2026 13:02:37 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/84b1ca75/eba96bb7.mp3" length="10454451" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/MEBSIYp-7jnIsKnnx_rCPHTdcheyjKiWHFZaFkL0h9M/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNGEz/YTM0OTdiNzY4NmJk/OWZiMzI3Mzg3N2Y1/M2I4Ny5wbmc.jpg"/>
      <itunes:duration>624</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 27, 2026):</strong></p><ul><li>A critical unauthenticated arbitrary file upload vulnerability in BreezeCache, a caching plugin with over 400,000 active installations, went from disclosure to mass exploitation in under 24 hours with over 22,000 exploit attempts blocked across nearly 5,000 sites</li><li>Attackers published a malicious version of the Bitwarden CLI package on NPM that harvested credentials from six different sources including SSH keys, cloud secret stores, and AI assistant configs during a 93-minute window before removal</li><li>The Bitwarden supply chain attack connects to a broader campaign targeting Checkmarx, with Team PCP claiming responsibility and links to the Shai-Hulud self-propagating NPM worm from 2025</li><li>Home security giant ADT confirmed a data breach after ShinyHunters listed the company on its leak site, with Have I Been Pwned tracking 5.5 million unique email addresses tied to the breach</li><li>ShinyHunters used a voice phishing attack to compromise an ADT employee's Okta SSO account and pivot to Salesforce, highlighting why phishing-resistant MFA like FIDO2 or WebAuthn is critical over SMS or TOTP</li><li>A 12-year-old privilege escalation vulnerability dubbed Pack2TheRoot in PackageKit lets any local unprivileged user install arbitrary packages as root, affecting Ubuntu, Debian, Fedora, and Rocky Linux since 2014</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:34 BreezeCache Critical File Upload Vulnerability and Mass Exploitation<br>3:50 Bitwarden CLI Supply Chain Attack via NPM<br>6:25 ADT Data Breach by ShinyHunters<br>7:49 Why Phishing-Resistant MFA Matters<br>8:54 PackageKit Privilege Escalation Vulnerability</p><p><strong>Story Links:</strong></p><ul><li><strong>Breeze Cache — Active Exploitation (CVE-2026-3844):</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0">https://www.wordfence.com/threat-intel/vulnerabilities/id/e342b1c0-6e7f-4e2c-8a52-018df12c12a0</a></li><li><strong>Bitwarden CLI Compromised in Checkmarx Supply Chain Attack:</strong> <a href="https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html">https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html</a></li><li><strong>SharePoint Patching Laggards — CVE-2026-32201:</strong> <a href="https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/">https://www.bleepingcomputer.com/news/security/over-1-300-microsoft-sharepoint-servers-vulnerable-to-ongoing-attacks/</a></li><li><strong>ADT Confirmed in ShinyHunters Breach:</strong> <a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/</a></li><li><strong>Pack2TheRoot — 12-Year-Old PackageKit Privilege Escalation (CVE-2026-41651):</strong> <a href="https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html">https://github.security.telekom.com/2026/04/pack2theroot-linux-local-privilege-escalation.html</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/84b1ca75/transcript.srt" type="application/x-subrip" rel="captions"/>
    </item>
    <item>
      <title>WordPress 30+ Plugin Supply Chain Attack | Wordfence Security News | Week of April 13, 2026</title>
      <itunes:episode>5</itunes:episode>
      <podcast:episode>5</podcast:episode>
      <itunes:title>WordPress 30+ Plugin Supply Chain Attack | Wordfence Security News | Week of April 13, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">056a29cd-c015-42cc-9bdc-992c54a63a6c</guid>
      <link>https://share.transistor.fm/s/170d5314</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 17 Apr 2026 14:18:02 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/170d5314/559faa1b.mp3" length="7873428" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/LQtcilkcSm2tBAJSVDhwQRFaLAtXbVC5RJDFVSlZWvI/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNGYy/YmQ2OGUzZjQxMGVi/YWM5ZGQxODE2YTcz/YWNlMC53ZWJw.jpg"/>
      <itunes:duration>489</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 13, 2026):</strong></p><ul><li>Over 30 WordPress plugins purchased on the Flippa marketplace were turned into backdoors that sat dormant for eight months before activating to inject SEO spam into wp-config.php, visible only to Googlebot</li><li>Smart Slider 3 Pro's update infrastructure was compromised, pushing a weaponized build through the official update channel for approximately six hours before being caught</li><li>Microsoft's second-largest Patch Tuesday ever fixes roughly 165 vulnerabilities including a SharePoint spoofing zero-day already under active exploitation and a Defender privilege escalation zero-day linked to the BlueHammer public exploit</li><li>Adobe released an emergency patch for an Acrobat Reader zero-day exploited in the wild since late 2025, discovered via malicious Russian-language PDFs about gas supply disruptions</li><li>ShinyHunters extortion group listed Rockstar Games on its leak site after stealing authentication tokens from cloud analytics platform Anadot and accessing Rockstar's connected Snowflake data warehouse</li><li>A critical pre-authentication remote code execution flaw in Marimo, an open-source Python notebook platform, was exploited within 10 hours of its advisory being published with no public proof of concept</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:26 Supply Chain Attack on 30+ Essential Plugin WordPress Plugins<br>2:08 Smart Slider 3 Pro Update Infrastructure Compromised<br>2:55 Kali Forms and Ninja Forms File Upload Exploitation Updates<br>3:21 Microsoft Patch Tuesday with SharePoint and Defender Zero-Days<br>5:31 Adobe Acrobat Reader Zero-Day Emergency Patch<br>6:26 ShinyHunters Breach of Rockstar Games via Anadot Tokens<br>7:16 Marimo RCE Exploited Within 10 Hours of Disclosure</p><p><strong>Story Links:</strong></p><ul><li><strong>30+ Plugins Backdoored After Flippa Acquisition:</strong> <a href="https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/">https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/</a></li><li><strong>Smart Slider 3 Pro — Supply Chain Compromise:</strong> <a href="https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise">https://smartslider.helpscoutdocs.com/article/2144-wordpress-security-advisory-smart-slider-3-pro-3-5-1-35-compromise</a></li><li><strong>Kali Forms exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/">https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-kali-forms-plugin/</a></li><li><strong>Ninja Forms File Upload exploitation update:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>April Patch Tuesday — SharePoint Zero-Day Exploited:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>BlueHammer — Defender Zero-Day:</strong> <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/">https://www.bleepingcomputer.com/news/microsoft/microsoft-april-2026-patch-tuesday-fixes-167-flaws-2-zero-days/</a></li><li><strong>Adobe Reader Zero-Day — Exploited Since Late 2025:</strong> <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">https://helpx.adobe.com/security/products/acrobat/apsb26-43.html</a></li><li><strong>Rockstar Games Breach via Third-Party Analytics:</strong> <a href="https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/">https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/</a></li><li><strong>Marimo RCE — Exploited in Under 10 Hours:</strong> <a href="https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours">https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/170d5314/transcription" type="text/html"/>
    </item>
    <item>
      <title>50,000 Site Ninja Forms File Upload Vulnerability | Anthropic Project Glasswing | Fortinet Zero Day | Wordfence Security News | April 6 2026</title>
      <itunes:episode>4</itunes:episode>
      <podcast:episode>4</podcast:episode>
      <itunes:title>50,000 Site Ninja Forms File Upload Vulnerability | Anthropic Project Glasswing | Fortinet Zero Day | Wordfence Security News | April 6 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">643fca4d-7d3c-463f-b8a2-b323d27469ff</guid>
      <link>https://share.transistor.fm/s/48f55f81</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </content:encoded>
      <pubDate>Fri, 10 Apr 2026 13:15:36 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/48f55f81/dbb20e4c.mp3" length="6688328" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/Ip0_QMQKCxHynR1LOuRBN0htY3dkJaNka7HDLXzrlzE/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMzI3/MzRiZGMwZDFkNjQ0/YWQ2NjY0MGQ0MDhh/ZTdlYi53ZWJw.jpg"/>
      <itunes:duration>415</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Apr 6, 2026):</strong></p><ul><li>An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk</li><li>A Fortinet zero-day actively exploited in the wild</li><li>A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout</li><li>Anthropic announces Project Glasswing</li><li>Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs</li></ul><p><strong>Story Links:</strong></p><ul><li><strong>Ninja Forms File Upload Vulnerability:</strong> <a href="https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/">https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/</a></li><li><strong>Fortinet Advisory:</strong> <a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></li><li><strong>CERT-EU Report:</strong> <a href="https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain">https://cert.europa.eu/blog/european-commission-cloud-breach-trivy-supply-chain</a></li><li><strong>Cisco / Trivy Fallout:</strong> <a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/</a></li><li><strong>Anthropic Glasswing Announcement:</strong> <a href="https://www.anthropic.com/">https://www.anthropic.com/</a></li><li><strong>Krebs on Security (REvil):</strong> <a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.</p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/48f55f81/transcription" type="text/html"/>
    </item>
    <item>
      <title>MW WP Form 200K Sites at Risk | Axios Hack | Cisco Breach | Wordfence Security News | March 30, 2026</title>
      <itunes:episode>3</itunes:episode>
      <podcast:episode>3</podcast:episode>
      <itunes:title>MW WP Form 200K Sites at Risk | Axios Hack | Cisco Breach | Wordfence Security News | March 30, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">4ae3b264-9506-47d0-94db-896a7a593cb7</guid>
      <link>https://share.transistor.fm/s/3e16c17d</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 03 Apr 2026 12:15:22 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/3e16c17d/1b14a3b4.mp3" length="7118160" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/JF1HiIbDHNBvOPZZAE5s76YU8eLwKIjnAz0bY-y8m7I/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mMDgw/M2U1YzAwZTdkOGZh/OGQxZjk4NWQxZTk5/NWNiNy53ZWJw.jpg"/>
      <itunes:duration>442</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 30, 2026): </strong></p><ul><li>Over 200,000 WordPress sites at risk from an unauthenticated arbitrary file move vulnerability in the MW WP Form plugin, allowing full site takeover</li><li>Massive spike in exploitation attempts targeting the Kali Forms RCE vulnerability, with activity increasing over 60x week-over-week</li><li>A major supply chain attack compromises the widely used Axios JavaScript library, distributing backdoored versions to developers worldwide Active exploitation of a critical Citrix NetScaler vulnerability enabling session hijacking and potential full appliance compromise</li><li>European Commission confirms a cloud breach with data theft claims by ShinyHunters</li><li>Cisco internal development environment breached via poisoned Trivy supply chain attack, exposing source code and credentials</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:30 MW WP Form Vulnerability<br>1:15 Kali Forms Exploitation Surge<br>1:55 Axios Supply Chain Attack<br>3:20 Citrix NetScaler Active Exploitation<br>4:57 European Commission Breach<br>5:50 Cisco Dev Environment Breach<br>6:47 Wrap up discussion</p><p><strong>Story Links:</strong></p><ul><li><a href="https://www.wordfence.com/blog/2026/04/200000-wordpress-sites-affected-by-arbitrary-file-move-vulnerability-in-mw-wp-form-wordpress-plugin/">MW WP Form Vulnerability</a></li><li><a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">Kali Forms Exploitation Update</a></li><li><a href="https://www.axios.com/2026/03/31/north-korean-hackers-implicated-in-major-supply-chain-attack">Axios Supply Chain Attack (Wiz)</a></li><li><a href="https://support.citrix.com/external/article/CTX696300/netscaler-adc-and-netscaler-gateway-secu.html">Citrix NetScaler Advisory</a></li><li><a href="https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_748/IP_26_748_EN.pdf">European Commission Breach (Bloomberg)</a></li><li><a href="https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/">Cisco / Trivy Supply Chain Attack</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/3e16c17d/transcription" type="text/html"/>
    </item>
    <item>
      <title>Iran-Linked Hackers Breach FBI Director's Email | Wordfence Security News| Week of March 23, 2026</title>
      <itunes:episode>2</itunes:episode>
      <podcast:episode>2</podcast:episode>
      <itunes:title>Iran-Linked Hackers Breach FBI Director's Email | Wordfence Security News| Week of March 23, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">58833c10-09ed-49d3-aaab-152e0e62aa9e</guid>
      <link>https://share.transistor.fm/s/d9a87871</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 27 Mar 2026 14:04:00 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/d9a87871/3a162eae.mp3" length="6361259" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/qoBjk1tfxmjKbg8VEBRV47nSJMfFo-vXI05QSmqgwXs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS83Y2Ni/MTkwMjM4Nzc1ZDA2/ZjliMjIxMmFkMGYz/Mjc4Mi53ZWJw.jpg"/>
      <itunes:duration>395</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 23, 2026): </strong></p><ul><li>Same-day exploitation of a critical RCE vulnerability in the Kali Forms plugin, attackers can achieve full admin takeover with a single request</li><li>Ongoing mass exploitation of the s2Member plugin targeting password reset functionality</li><li>Breaking News: Iran-linked hackers claim breach of FBI Director Kash Patel’s personal email</li><li>A critical Cisco firewall management vulnerability exploited as a zero-day by ransomware actors</li><li>FBI and CISA warn of phishing campaigns targeting messaging app accounts</li></ul><p><strong>Timestamps:</strong></p><p>0:00 Introduction<br>0:25 Kali Forms RCE Vulnerability<br>1:34 s2Member Mass Exploitation<br>2:20 Breaking News – FBI Email Breach<br>2:45 Cisco Firewall RCE Exploitation<br>5:03 Messaging App Phishing Campaigns</p><p><strong>Story Links:</strong></p><ul><li><strong>Kali Forms RCE Vulnerability:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/kali-forms/kali-forms-249-unauthenticated-remote-code-execution-via-form-process</a></li><li><strong>s2Member Exploitation Campaign:</strong> <a href="https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover">https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/s2member/s2member-260127-unauthenticated-privilege-escalation-via-account-takeover</a></li><li><strong>Cisco Firewall Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</a></li><li><strong>Interlock Ransomware Coverage:</strong> <a href="https://www.ic3.gov/PSA/2026/PSA260320">https://www.ic3.gov/PSA/2026/PSA260320</a></li><li><strong>Reuters – FBI Email Breach:</strong> <a href="https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/">https://www.reuters.com/world/us/iran-linked-hackers-claim-breach-of-fbi-directors-personal-email-doj-official-2026-03-27/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress, WordPress Security, Cybersecurity</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/d9a87871/transcription" type="text/html"/>
    </item>
    <item>
      <title>30,000 Sites at Risk, Cisco Zero-Day &amp; Stryker Attack | Wordfence Security News | Week of Mar 9, 2026</title>
      <itunes:episode>1</itunes:episode>
      <podcast:episode>1</podcast:episode>
      <itunes:title>30,000 Sites at Risk, Cisco Zero-Day &amp; Stryker Attack | Wordfence Security News | Week of Mar 9, 2026</itunes:title>
      <itunes:episodeType>full</itunes:episodeType>
      <guid isPermaLink="false">08e87077-14c9-4622-b894-f31d76add52e</guid>
      <link>https://share.transistor.fm/s/60882fd7</link>
      <description>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </description>
      <content:encoded>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </content:encoded>
      <pubDate>Fri, 13 Mar 2026 14:00:00 -0700</pubDate>
      <author>Wordfence</author>
      <enclosure url="https://media.transistor.fm/60882fd7/327d379d.mp3" length="5525345" type="audio/mpeg"/>
      <itunes:author>Wordfence</itunes:author>
      <itunes:image href="https://img.transistorcdn.com/2qAiJI6oMaDilR9ZKIvjtF5_zDViH_fPv3L6USsuIYs/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9mNmEz/ZTM4NDgyMjIyZDBh/MGQ1NGVjNzk4ZTVh/OTAyYy53ZWJw.jpg"/>
      <itunes:duration>343</itunes:duration>
      <itunes:summary>
        <![CDATA[<p><strong>This week in Wordfence Security News (Week of Mar 9, 2026): </strong></p><ul><li>A critical auth bypass in Tutor LMS Pro exposes 30,000+ WordPress sites — attackers can hijack admin accounts via a Google sign-in flaw</li><li>An unauthenticated SQL injection in Ally (400K+ sites)</li><li>Microsoft Patch Tuesday with ~80 fixes including AI-related exploits</li><li>A max-severity Cisco SD-WAN zero-day exploited since 2023</li><li>Iran-linked group Handala's claimed attack on medical device maker Stryker.</li></ul><p><strong>Timestamps:<br></strong><br>0:00 Introduction<br>0:22 Tutor LMS Pro Authentication Bypass<br>1:31 Ally WordPress Plugin SQL Injection<br>1:50 Microsoft Patch Tuesday<br>2:46 Cisco SD-WAN Zero-Day<br>4:26 Handala Attack on Stryker<br>5:03 Iranian Drone Strikes on AWS Data Centers</p><p><strong>Story Links:</strong></p><ul><li><strong>Tutor LMS Pro Auth Bypass: </strong><a href="https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/30000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-tutor-lms-pro-wordpress-plugin/</a></li><li><strong>Ally Plugin SQL Injection:</strong> <a href="https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/">https://www.wordfence.com/blog/2026/03/400000-wordpress-sites-affected-by-unauthenticated-sql-injection-vulnerability-in-ally-wordpress-plugin/</a></li><li><strong>Microsoft Patch Tuesday:</strong> <a href="https://msrc.microsoft.com/update-guide/">https://msrc.microsoft.com/update-guide/</a></li><li><strong>Cisco SD-WAN Advisory:</strong> <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</a></li><li><strong>Iran Cyber Retaliation:</strong> <a href="https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/">https://industrialcyber.co/reports/cyber-retaliation-surges-after-us-israel-strikes-on-iran-as-hacktivists-hit-governments-defense-critical-sectors/</a></li><li><strong>Stryker Cyberattack (WSJ):</strong> <a href="https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c">https://www.wsj.com/articles/stryker-hit-with-suspected-iran-linked-cyberattack-52f6615c</a></li><li><strong>AWS Data Centers Struck (BBC):</strong> <a href="https://www.bbc.com/news/articles/cgk28nj0lrjo">https://www.bbc.com/news/articles/cgk28nj0lrjo</a></li><li><strong>Weekly Vulnerability Report:</strong> <a href="https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/">https://www.wordfence.com/blog/2026/03/wordfence-intelligence-weekly-wordpress-vulnerability-report-march-2-2026-to-march-8-2026/</a></li></ul><p>Stay informed and secure: get the latest WordPress security news on the <a href="https://www.wordfence.com/blog/">Wordfence blog</a> or subscribe to the <a href="https://www.wordfence.com/subscribe-to-the-wordfence-email-list/">WordPress Security Newsletter</a>.  </p>]]>
      </itunes:summary>
      <itunes:keywords>Wordfence, WordPress News, WordPress Security News, WordPress, WordPress Security, Cybersecurity, Cybersecurity News</itunes:keywords>
      <itunes:explicit>No</itunes:explicit>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.vtt" type="text/vtt" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.srt" type="application/x-subrip" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.json" type="application/json" rel="captions"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription.txt" type="text/plain"/>
      <podcast:transcript url="https://share.transistor.fm/s/60882fd7/transcription" type="text/html"/>
    </item>
  </channel>
</rss>
