Breeze Caching Plugin for WordPress
A WordPress caching plugin vulnerable to CVE-2026-3844, exploited by WP-SHELLSTORM to backdoor over 17,000 sites. Fixed in version 2.4.5.
A WordPress caching plugin vulnerable to CVE-2026-3844, exploited by WP-SHELLSTORM to backdoor over 17,000 sites. Fixed in version 2.4.5.
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way…
A high-severity authentication bypass vulnerability in the UpdraftPlus WordPress backup plugin, rated 8.1 by Wordfence. It is now patched and has been…
A hidden plugin installed by the attacker acts as a web shell, allowing remote command execution on the compromised server without authentication.
Awesome Motive is the parent company of PushEngage, OptinMonster, and TrustPulse. The company had not commented on the two larger plugins as…
Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use…
Lorem Ipsum Loader is a nascent loader and backdoor active since February 2026. It is delivered through ClickFix lures on compromised WordPress…
Beloved PBN Entegrasyonu is a fake WordPress plugin used by a Turkish-speaking threat actor to inject hidden backlinks for a Private Blog…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to…