Hackers exploit file upload bug in Breeze Cache WordPress plugin
2026-04-24T07:23:32Z•7a37c75dc9ad35f1c839632c5f0fef147bd53bff33807bca9da8c371228a126e
CVE-2025-29635apt-state-backed','microsoft-365','outlook','slack','discord'arbitrary-file-uploadbitwardenbluehammerbreeze-cachecheckmarxcisacredential-theftd-linkdata-exfiltrationdocker-image-compromisegopherwhisperkicsmicrosoft-defendermirainpm-compromiseopen-vsxplugin-exploitransomwaresupply-chaintrigonavscode-extensionwordpresszero-day
What happened
Multiple active and emerging threats reported: attackers are actively exploiting an arbitrary file upload bug in the Breeze Cache WordPress plugin; a malicious @bitwarden/cli npm package was published to steal developer credentials; Checkmarx KICS supply-chain artifacts (Docker images, VSCode/Open VSX extensions) were compromised to harvest developer data; Trigona ransomware campaigns now use a custom CLI exfiltration tool; a Mirai campaign is exploiting CVE-2025-29635 in EoL D-Link DIR-823X routers to recruit devices; CISA ordered federal patching for a Microsoft Defender privilege-escalation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7a37c75dc9ad35f1c839632c5f0fef147bd53bff33807bca9da8c371228a126e
- Enrichment time
- 2026-04-24T07:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.