Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 in Operation Dream Job Attacks
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…
Cybersecurity researchers have uncovered a supply chain attack targeting WordPress plugin vendor BdThemes, leading to the temporary suspension of several plugins from…
CVE-2026-18072 is a vulnerability in the Advanced Responsive Video Embedder WordPress plugin that was exploited in a supply chain attack to grant…
w2.js is a JavaScript payload used in the BdThemes supply chain attack. It contacts a C2 server, creates rogue admin accounts, installs…
x.js is an alternate payload in the BdThemes attack that generates deterministic administrative credentials based on the victim website's hostname, allowing attackers…
The magic-login backdoor is a persistence module installed in the mu-plugins directory that allows unauthenticated administrative entry via a URL parameter targeting…
BdThemes is a WordPress plugin vendor whose plugins were compromised in a supply chain attack via poisoned JSON data, leading to temporary…
Element Pack Addons for Elementor is a WordPress plugin with over 100,000 active installs that was affected by the BdThemes supply chain…
Live Copy Paste for Elementor is a WordPress plugin with 6,000+ active installs that was affected by the BdThemes supply chain attack…
Pixel Gallery Addons for Elementor is a WordPress plugin affected by the BdThemes supply chain attack and temporarily closed.