PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

2026-09-16T20:52:09Z•2fed83df8b5ce904067a8a5f6b9dc5620946c93e9c8c9e8c5cef12a7d9a769af
CVE-2026-86218AI-securityAndroidIranLazarusMicrosoft-365North KoreaOAuth-token-theftRATWooCommerceWordPresscloud-identitycredential-theftcybercrimeincident-responseinsider-threatmalwarephishingransomwarespywarestate-sponsored-activitysupply-chain-securityvulnerability-exploitationwebshellzero-day

What happened

Infosecurity Magazine coverage highlights active exploitation of critical vulnerabilities, including WordPress/WooCommerce, GitLab, SAP, Microsoft, TP-Link cameras, and N-able products. Other reporting covers ransomware, phishing and credential theft, malware targeting Android and cloud identities, software supply-chain compromise, insider and non-human identity risks, AI-related security issues, cybercrime operations, and state-sponsored activity involving Iran and North Korea.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
2fed83df8b5ce904067a8a5f6b9dc5620946c93e9c8c9e8c5cef12a7d9a769af
Enrichment time
2026-09-16T20:52:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.