14,971 WordPress Sites Cleaned in Global SocGholish Takedown
2026-06-20T02:51:46Z•ce269c4b688f23421cb92f8c51a7fd8897586af829a06da1763d6f3505d490ef
CISACisco ISEDialog leakDragonForceElasticsearchF5 NGINXFortiBleedFortinetKnown Exploited VulnerabilityMicrosoft DefenderOperation EndGameRoguePlanetSocGholishSplunkWordPressclippercredentialscryptocurrencydata-leaklaw-enforcementransomwaresupply-chaintakdown
What happened
Multiple high-impact incidents and vulnerabilities reported: a multinational law‑enforcement operation (Operation EndGame) dismantled the SocGholish infrastructure, taking down 106 servers and cleaning ~14,971 WordPress sites used to serve fake-update malware. U.S. CISA added a critical Splunk Enterprise flaw (CVE-2026-20253, CVSS 9.8) to its Known Exploited Vulnerabilities catalog. Major data exposures and campaigns were disclosed, including a 24 billion‑record credential leak, a leak of membership/login data from Peter Thiel’s Dialog site, and a Tor‑based clipper campaign targeting crypto‑se
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- ce269c4b688f23421cb92f8c51a7fd8897586af829a06da1763d6f3505d490ef
- Enrichment time
- 2026-06-20T02:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.