Hackers exploit critical flaw in Ninja Forms WordPress plugin

2026-04-08T01:23:30Zcce58084639ab3b9b0dfc3fced0bf8a89824e5a695d96d5589109a03f6531e44
BlueHammerCISACVE-2025-59528FlowiseFortinet EMSFrostArmadaGPUGPUBreachIranian APTMicrosoft 365 credential theftMikroTikNinja FormsRCERockwell Allen-Bradley PLCs (ICS)RowhammerSaaS integrator breachSnowflakeTP-LinkWindows zero-dayWordPressdata theftfile uploadremote code executionrouter DNS hijacksupply chain

What happened

Multiple high-impact security incidents and vulnerabilities were reported: a critical unauthenticated file-upload flaw in the Ninja Forms File Uploads premium WordPress add-on is being exploited, enabling arbitrary file upload and potential remote code execution; the max-severity Flowise RCE (CVE-2025-59528) is now exploited in the wild; and new attack techniques such as GPUBreach (GPU Rowhammer) and a leaked Windows privilege-escalation exploit (“BlueHammer”) increase risk of full system compromise. Supply-chain and credential-theft incidents continue—Snowflake customers were hit after a SaaS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
cce58084639ab3b9b0dfc3fced0bf8a89824e5a695d96d5589109a03f6531e44
Enrichment time
2026-04-08T01:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.