GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
2026-06-02T08:51:47Z•c992e83384399d152d3bd26fab767a34fae98eb5f0e8094000a113957955db82
CIFSwitchCISA-KEVCVE-2026-0257CVE-2026-26980CVE-2026-8732data-leakglobalprotectinvisible-unicodelazaruslinux-privilege-escalationlocation-data-exposuremalwarepalo-altopan-osransomware-trendsshinyhunterssteam-C2supply-chainwordpresswp-maps-pro
What happened
Feed highlights multiple active and high-impact threats: GoDaddy found malware on ~1,980 WordPress sites that hide C2 instructions in Steam profile comments using invisible Unicode; a WP Maps Pro vulnerability (CVE-2026-8732) allows unauthenticated attackers to create WordPress admin accounts; Palo Alto PAN-OS GlobalProtect cookie-forgery bug (CVE-2026-0257, CVSS 7.8) is being actively exploited and was added to CISA's KEV list; a 19-year-old Linux logic bug dubbed CIFSwitch can lead to local root escalation on several distributions; and a range of supply-chain and data-exfiltration incidents—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- c992e83384399d152d3bd26fab767a34fae98eb5f0e8094000a113957955db82
- Enrichment time
- 2026-06-02T08:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.