Turkish-Speaking Threat Actor Behind WordPress PBN Backlink Campaign
A Turkish-speaking threat actor is operating a campaign that compromises WordPress sites to inject hidden backlinks for a Private Blog Network (PBN),…
A Turkish-speaking threat actor is operating a campaign that compromises WordPress sites to inject hidden backlinks for a Private Blog Network (PBN),…
Sucuri researcher Puja Srivastava analyzed a WordPress compromise campaign involving a fake plugin 'Beloved PBN Entegrasyonu' used for hidden backlink injection by…
Cloud-based dashboard service for managing WordPress and Joomla websites that discovered and reported zero-day exploitation of CVE-2026-48939 and CVE-2026-56291.
According to a new analysis by Intruder, 60% of organizations have at least one HTTP panel exposed, 49% have a risky port…
An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to promote a cryptocurrency clipboard hijacker.…
WordPress is the content management system affected by the BdThemes supply chain attack, which exploited a vulnerability in a promotional banner component…
Threat actors are actively exploiting a recently patched medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin, which is installed on…
The popular CMS. Versions 4.7 through 7.0 are affected by CVE-2026-65640, allowing Author-level users to achieve RCE via malicious Postscript uploads. Patched…
CVE-2026-4020 is a medium-severity information disclosure vulnerability in the Gravity SMTP WordPress plugin, affecting versions prior to 2.1.5. The flaw allows unauthenticated…
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels…