GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure

2026-06-02T08:51:47Zc992e83384399d152d3bd26fab767a34fae98eb5f0e8094000a113957955db82
CIFSwitchCISA-KEVCVE-2026-0257CVE-2026-26980CVE-2026-8732data-leakglobalprotectinvisible-unicodelazaruslinux-privilege-escalationlocation-data-exposuremalwarepalo-altopan-osransomware-trendsshinyhunterssteam-C2supply-chainwordpresswp-maps-pro

What happened

Feed highlights multiple active and high-impact threats: GoDaddy found malware on ~1,980 WordPress sites that hide C2 instructions in Steam profile comments using invisible Unicode; a WP Maps Pro vulnerability (CVE-2026-8732) allows unauthenticated attackers to create WordPress admin accounts; Palo Alto PAN-OS GlobalProtect cookie-forgery bug (CVE-2026-0257, CVSS 7.8) is being actively exploited and was added to CISA's KEV list; a 19-year-old Linux logic bug dubbed CIFSwitch can lead to local root escalation on several distributions; and a range of supply-chain and data-exfiltration incidents—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
c992e83384399d152d3bd26fab767a34fae98eb5f0e8094000a113957955db82
Enrichment time
2026-06-02T08:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure · Baitaphish