Hackers exploit file upload bug in Breeze Cache WordPress plugin

2026-04-24T07:23:32Z7a37c75dc9ad35f1c839632c5f0fef147bd53bff33807bca9da8c371228a126e
CVE-2025-29635apt-state-backed','microsoft-365','outlook','slack','discord'arbitrary-file-uploadbitwardenbluehammerbreeze-cachecheckmarxcisacredential-theftd-linkdata-exfiltrationdocker-image-compromisegopherwhisperkicsmicrosoft-defendermirainpm-compromiseopen-vsxplugin-exploitransomwaresupply-chaintrigonavscode-extensionwordpresszero-day

What happened

Multiple active and emerging threats reported: attackers are actively exploiting an arbitrary file upload bug in the Breeze Cache WordPress plugin; a malicious @bitwarden/cli npm package was published to steal developer credentials; Checkmarx KICS supply-chain artifacts (Docker images, VSCode/Open VSX extensions) were compromised to harvest developer data; Trigona ransomware campaigns now use a custom CLI exfiltration tool; a Mirai campaign is exploiting CVE-2025-29635 in EoL D-Link DIR-823X routers to recruit devices; CISA ordered federal patching for a Microsoft Defender privilege-escalation

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7a37c75dc9ad35f1c839632c5f0fef147bd53bff33807bca9da8c371228a126e
Enrichment time
2026-04-24T07:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.