ShapedPlugin update flow hacked to infect WordPress sites
2026-06-18T13:23:45Z•b845d075b65356ccd85efa60b6e012d779490ecbdf16169430a0b86d77812ff2
applebeats-studio-budsbluetooth-eavesdroppingcisacredentials-leakdefenderf5fortibleedfortinetjcejetbrainsjoomlamalicious-plugins','ai-api-keys','data-breach','shinyhunters','kmicrosoftnginxofficerceremote-code-executionrogueplanetshapedpluginsupply-chainvpn-credentialswindows-server-2016wordpresszero-day
What happened
Multiple high-impact security incidents reported 17–18 Jun 2026: a supply‑chain compromise of ShapedPlugin distributed backdoored WordPress plugin updates to paying customers; a large “FortiBleed” leak exposing ~73,932 Fortinet/FortiGate VPN credentials and firewall URLs; out‑of‑band F5 patches for multiple NGINX vulnerabilities including two critical RCEs; and a CISA order to urgently patch a maximum‑severity Joomla JCE plugin flaw actively exploited in the wild. Microsoft is addressing a Defender zero‑day called “RoguePlanet” while also fixing Windows Server 2016 update failures and Office‑l
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- b845d075b65356ccd85efa60b6e012d779490ecbdf16169430a0b86d77812ff2
- Enrichment time
- 2026-06-18T13:23:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.