ShapedPlugin update flow hacked to infect WordPress sites

2026-06-18T13:23:45Zb845d075b65356ccd85efa60b6e012d779490ecbdf16169430a0b86d77812ff2
applebeats-studio-budsbluetooth-eavesdroppingcisacredentials-leakdefenderf5fortibleedfortinetjcejetbrainsjoomlamalicious-plugins','ai-api-keys','data-breach','shinyhunters','kmicrosoftnginxofficerceremote-code-executionrogueplanetshapedpluginsupply-chainvpn-credentialswindows-server-2016wordpresszero-day

What happened

Multiple high-impact security incidents reported 17–18 Jun 2026: a supply‑chain compromise of ShapedPlugin distributed backdoored WordPress plugin updates to paying customers; a large “FortiBleed” leak exposing ~73,932 Fortinet/FortiGate VPN credentials and firewall URLs; out‑of‑band F5 patches for multiple NGINX vulnerabilities including two critical RCEs; and a CISA order to urgently patch a maximum‑severity Joomla JCE plugin flaw actively exploited in the wild. Microsoft is addressing a Defender zero‑day called “RoguePlanet” while also fixing Windows Server 2016 update failures and Office‑l

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b845d075b65356ccd85efa60b6e012d779490ecbdf16169430a0b86d77812ff2
Enrichment time
2026-06-18T13:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ShapedPlugin update flow hacked to infect WordPress sites · Baitaphish