<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: WordPress Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving WordPress.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution</title><link>https://elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend</link><guid isPermaLink="false">cst-3046</guid><description>On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain affecting WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 through a route confusion flaw in the REST batch endpoint. Proof-of-concept tools circulated within hours, with attackers either escalating through SQL injection to upload malicious plugins or dropping webshells directly to disk, resulting in command execution via the web process. Defenders observe PHP and web server runtimes spawning shells, plugin directories appearing under wp-content/plugins/, and consistent post-exploitation discovery activity across vulnerable hosts.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Critical wp2shell WordPress flaws exploited to install webshells</title><link>https://bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells</link><guid isPermaLink="false">cst-2951</guid><description>Attackers are actively exploiting two critical vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137, to deploy webshells and malicious plugins on compromised servers. The flaws in the wp2shell vulnerability suite allow persistent remote access and malicious code installation.</description><pubDate>Tue, 21 Jul 2026 16:41:50 GMT</pubDate></item><item><title>Captive Portal Detection</title><link>https://isc.sans.edu/diary/rss/33172</link><guid isPermaLink="false">cst-2928</guid><description>This article explains how modern operating systems and browsers detect captive portals on public WiFi networks by attempting to access specific HTTP URLs and checking for redirect responses. Different platforms use different detection URLs: Windows checks msftconnecttest.com, Apple uses captive.apple.com, Android and Chrome use generate_204 endpoints, and Firefox uses detectportal.firefox.com. Understanding these detection mechanisms can help network administrators and security analysts recognize benign traffic patterns and assist users who encounter connectivity issues.</description><pubDate>Tue, 21 Jul 2026 13:44:56 GMT</pubDate></item><item><title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title><link>https://cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog</link><guid isPermaLink="false">cst-2931</guid><description>CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: CVE-2021-27137 (DD-WRT buffer overflow), CVE-2026-0770 (Langflow control sphere inclusion), CVE-2026-63030 (WordPress interpretation conflict), and CVE-2026-60137 (WordPress SQL injection). Binding Operational Directive 26-04 requires federal agencies to prioritize patching KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk</title><link>https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk</link><guid isPermaLink="false">cst-2851</guid><description>Two critical security flaws in WordPress have been discovered and exploited by attackers, potentially affecting tens of millions of websites running the platform. The vulnerabilities allow for remote code execution and unauthorized access to affected systems.</description><pubDate>Mon, 20 Jul 2026 15:35:37 GMT</pubDate></item><item><title>wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core</title><link>https://tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution</link><guid isPermaLink="false">cst-2848</guid><description>Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. Active exploitation began within days of the July 17, 2026 disclosure, with public proof-of-concept code circulating and multiple security firms confirming attacks in the wild. Patches are available in WordPress 7.0.2 and 6.9.5, with WordPress.org enabling forced automatic updates for affected installations.</description><pubDate>Mon, 20 Jul 2026 13:36:32 GMT</pubDate></item><item><title>⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More</title><link>https://thehackernews.com/2026/07/weekly-recap-wordpress-rce-sonicwall-0.html</link><guid isPermaLink="false">cst-2838</guid><description>This weekly recap highlights multiple critical vulnerabilities discovered in WordPress, SonicWall, and SharePoint products, along with attacks targeting artificial intelligence services. The incidents involved simple attack vectors such as exposed systems, insufficient input validation, outdated drivers, and malicious prompts that enabled remote code execution, data theft, and security tool circumvention.</description><pubDate>Mon, 20 Jul 2026 13:32:26 GMT</pubDate></item><item><title>20th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/20th-july-threat-intelligence-report</link><guid isPermaLink="false">cst-2835</guid><description>Ernst and Young disclosed a breach involving a compromised third-party IT support platform exposing client documents and tax information. Supply chain compromises affected the Jscrambler JavaScript package and multiple artificial intelligence tools including Claude Code, DeepSeek, and Grok Build. Microsoft released 622 patches in July including fixes for two actively exploited vulnerabilities in SharePoint Server and Active Directory Federation Services, while WordPress issued emergency updates for critical remote code execution flaws.</description><pubDate>Mon, 20 Jul 2026 12:18:41 GMT</pubDate></item><item><title>Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs</title><link>https://helpnetsecurity.com/2026/07/19/week-in-review-oauth-client-ids-spoofed-sonicwall-sma-appliances-targeted-in-zero-day-attacks</link><guid isPermaLink="false">cst-2799</guid><description>WordPress released version 7.0.2 to address one critical and one high severity security vulnerability requiring immediate patching. A separate incident involved fake OAuth IDs bypassing sign-in logs, and a deep research agent was used to test cloud security by running a language model against live cloud accounts.</description><pubDate>Sun, 19 Jul 2026 07:09:58 GMT</pubDate></item><item><title>WordPress Core "wp2shell" RCE flaws get public exploits, patch now</title><link>https://bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now</link><guid isPermaLink="false">cst-2797</guid><description>Public exploits are now available for critical remote code execution vulnerabilities in WordPress Core known as 'wp2shell'. WordPress administrators should apply patches immediately to mitigate active exploitation risk.</description><pubDate>Sat, 18 Jul 2026 17:22:47 GMT</pubDate></item><item><title>Two new high severity WordPress vulnerabilities, patch immediately!</title><link>https://helpnetsecurity.com/2026/07/18/wordpress-vulnerabilities-wp2shell-cve-2026-60137-cve-2026-60137</link><guid isPermaLink="false">cst-2796</guid><description>WordPress released version 7.0.2 to address one critical and one high severity vulnerability. The issues include CVE-2026-60137, a facilitated SQL injection flaw, and a separate REST API batch-route confusion vulnerability leading to remote code execution. Both require immediate patching across affected WordPress 6.9 installations.</description><pubDate>Sat, 18 Jul 2026 14:57:20 GMT</pubDate></item><item><title>New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code</title><link>https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html</link><guid isPermaLink="false">cst-2783</guid><description>A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.</description><pubDate>Fri, 17 Jul 2026 21:20:10 GMT</pubDate></item><item><title>We built a vulnerability vending machine: AI tokens in, zero-days out</title><link>https://bleepingcomputer.com/news/security/we-built-a-vulnerability-vending-machine-ai-tokens-in-zero-days-out</link><guid isPermaLink="false">cst-2593</guid><description>Intruder built an AI system that combines code analysis with large language models to automatically discover previously unknown software vulnerabilities. The system identified and exploited a WordPress plugin zero-day, with additional findings currently under responsible disclosure.</description><pubDate>Wed, 15 Jul 2026 14:01:11 GMT</pubDate></item><item><title>Someone Is Scanning for Your MCP Servers and AI Assistant Credentials</title><link>https://isc.sans.edu/diary/rss/33150</link><guid isPermaLink="false">cst-2377</guid><description>Distributed scanners at internet scale are systematically probing for Model Context Protocol (MCP) servers, AI assistant configuration files, and locally exposed large language model endpoints, including sending valid JSON-RPC 2.0 handshakes to test for functional MCP implementations. The scanning activity, originating from 49 distinct IP addresses over a two-week period, also targets AI assistant credential and configuration files from tools like Claude and Cursor that developers may accidentally expose in web roots.</description><pubDate>Mon, 13 Jul 2026 04:22:02 GMT</pubDate></item><item><title>Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites</title><link>https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html</link><guid isPermaLink="false">cst-2321</guid><description>A misconfigured server belonging to a cybercrime group was left publicly accessible for three weeks, exposing hacking tools, activity logs, and a target list of over 1.4 million websites. The exposure revealed operational details of a mass site-hacking campaign, though the actual number of compromised sites was significantly smaller than the target list. Researchers were able to analyze the backdoor tool (WP-SHELLSTORM) and understand the group's infrastructure and tactics.</description><pubDate>Fri, 10 Jul 2026 11:30:02 GMT</pubDate></item><item><title>US Army websites defaced with pro-Kurdish sentiments, insults to Trump</title><link>https://cyberscoop.com/us-army-websites-defaced-404-hijacking-kurdistan</link><guid isPermaLink="false">cst-496</guid><description>Multiple U.S. Army websites, including oil.army.mil and ai2c.army.mil, were defaced through 404 hijacking that displayed pro-Kurdish messages and insults to President Trump and Ambassador Tom Barrack. The compromise affected error pages on legacy third-party platforms not connected to the Army's enterprise network; the affected pages were taken offline after discovery. It remains unclear how the attackers gained access to modify error pages or whether the intrusion extends beyond the visible defacement.</description><pubDate>Mon, 06 Jul 2026 17:50:25 GMT</pubDate></item><item><title>Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge</title><link>https://recordedfuture.com/blog/expertise-meets-algorithm-intelligence-edge</link><guid isPermaLink="false">cst-1942</guid><description>Recorded Future's Insikt Group combines human expertise with automated data analysis to identify threats and adversary operations. The team uses infrastructure detection, victim identification through network traffic analysis, and multi-source validation across over one million data sources to uncover threat actor activities. This hybrid approach enables analysts to detect malicious infrastructure and ongoing compromises faster than traditional methods while providing context that automated systems alone would miss.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate></item><item><title>From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker</title><link>https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker</link><guid isPermaLink="false">cst-596</guid><description>A threat actor is distributing a Rust-based clipboard hijacker disguised as cryptocurrency trading bots and game prediction tools across multiple platforms, including fake GitHub and SourceForge repositories, a YouTube channel with AI-generated content, and compromised news sites. The operation uses coordinated fake accounts, inflated engagement metrics, and manipulated VirusTotal reputation signals to create a false appearance of legitimacy and trustworthiness. Once installed, the malware monitors the clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, generating illicit cryptocurrency transactions.</description><pubDate>Wed, 17 Jun 2026 13:38:55 GMT</pubDate></item><item><title>Help-Desk Lures Drop KongTuke's Evolved ModeloRAT</title><link>https://reliaquest.com/blog/threat-spotlight-help-desk-lures-drop-kongtukes-evolved-modelorat</link><guid isPermaLink="false">cst-2116</guid><description>KongTuke, a financially motivated initial access broker, has shifted from web-based delivery methods to impersonating help-desk staff in external Microsoft Teams chats to distribute ModeloRAT, a remote access trojan with redundant command-and-control infrastructure and layered persistence mechanisms. The group achieves persistent access within five minutes of victims executing a single PowerShell command, and rotates through multiple Microsoft 365 tenants and persistence triggers to evade defensive measures. This represents the first known use of a collaboration platform by KongTuke for initial access and signals a broader trend of threat actors moving social engineering tactics from email and web vectors to Teams and similar platforms.</description><pubDate>Thu, 14 May 2026 09:00:00 GMT</pubDate></item></channel></rss>