Hackers exploit file upload bug in Breeze Cache WordPress plugin
2026-04-24T01:23:43Z•bd1794537032b981d4c5fd14f54896e67e766da6425cc3a6891749c7f1dd261a
active-exploitationbitwardenbluehammerbreeze-cachecheckmarxcredential-stealerdata-breachdockerfile-uploadkicskybermicrosoftmirai-botnetnpmpassword-resetpost-quantum-encryptionransomwareritualssocial-engineeringsupply-chainsupply-chain-compromisetrigonavscode-extensionwordpresszero-day
What happened
Multiple active security incidents and supply-chain compromises were reported: attackers are actively exploiting a critical unauthenticated file‑upload flaw in the Breeze Cache WordPress plugin; a malicious @bitwarden/cli npm package briefly published credential‑stealing malware; Trigona ransomware campaigns are using a custom CLI exfiltration tool; and Checkmarx KICS developer tooling (Docker images, VSCode/Open VSX extensions) was compromised to harvest developer data. CISA ordered federal agencies to patch a Microsoft Defender privilege‑escalation zero‑day dubbed “BlueHammer.” A new Mirai‑l
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- bd1794537032b981d4c5fd14f54896e67e766da6425cc3a6891749c7f1dd261a
- Enrichment time
- 2026-04-24T01:23:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.