Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844)

2026-04-25T20:51:58Z80596b130e609c6bc2a5b0dd347f1b5cb7ecb0194fd536ab86a2ceaa80dfef47
CVE-2026-28950CVE-2026-33825CVE-2026-3844CVE-2026-41651PackageKitRAMPbackdoorbitwardenbreeze-cachecheckmarxchina-linkedcisco-asadata-breachfirestarteriosiot-botnetlinuxmicrosoft-defenderprivilege-escalationransomware-marketplaceritualssupply-chainunauthenticated-file-uploadweb-applicationwordpress

What happened

Multiple high-impact security stories: attackers are actively exploiting a critical unauthenticated file-upload flaw in the Breeze Cache WordPress plugin (CVE-2026-3844) affecting hundreds of thousands of sites. Other notable incidents include a persistent FIRESTARTER backdoor on a Cisco ASA/Firepower device in a U.S. federal network, a 12-year local privilege-escalation bug in PackageKit (CVE-2026-41651), and a Bitwarden CLI compromise tied to the Checkmarx supply-chain campaign. Additional coverage: a Signal-based phishing targeting Germany’s Bundestag President, NCSC warnings about China‑at

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
80596b130e609c6bc2a5b0dd347f1b5cb7ecb0194fd536ab86a2ceaa80dfef47
Enrichment time
2026-04-25T20:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) · Baitaphish