1.
2.
BdThemes plugins supply-chain hack creates rogue WordPress admins
(bleepingcomputer.com)
3.
Pocket Casts just released a brand-new Apple TV app
(9to5mac.com)
4.
Re: Bye Bye Gravatar
(news.ycombinator.com)
5.
Ransomware Is Accelerating, But It's Not Because of AI
(darkreading.com)
6.
Critical wp2shell WordPress flaws exploited to install webshells
(bleepingcomputer.com)
7.
8.
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
(darkreading.com)
9.
10.
Hacker wipes Romania's land registry database
(news.ycombinator.com)
11.
Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25
(news.ycombinator.com)
12.
13.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
(bleepingcomputer.com)
14.
16.
Australia warns of global campaign targeting vulnerable CMS platforms
(bleepingcomputer.com)
17.
18.
New Prinz Eugen ransomware prioritizes recent files for encryption
(bleepingcomputer.com)
19.
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
(bleepingcomputer.com)
20.
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
(bleepingcomputer.com)
21.
ShapedPlugin update flow hacked to infect WordPress sites
(bleepingcomputer.com)
22.
23.
24.
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
(darkreading.com)
25.
26.
OptinMonster WordPress plugin hacked in CDN supply-chain attack
(bleepingcomputer.com)
27.
28.
29.
Critical Kirki flaw exploited to hijack WordPress admin accounts
(bleepingcomputer.com)
30.
WordPress malware campaign hides payloads in Steam profiles
(bleepingcomputer.com)