14,971 WordPress Sites Cleaned in Global SocGholish Takedown

2026-06-20T02:51:46Zce269c4b688f23421cb92f8c51a7fd8897586af829a06da1763d6f3505d490ef
CISACisco ISEDialog leakDragonForceElasticsearchF5 NGINXFortiBleedFortinetKnown Exploited VulnerabilityMicrosoft DefenderOperation EndGameRoguePlanetSocGholishSplunkWordPressclippercredentialscryptocurrencydata-leaklaw-enforcementransomwaresupply-chaintakdown

What happened

Multiple high-impact incidents and vulnerabilities reported: a multinational law‑enforcement operation (Operation EndGame) dismantled the SocGholish infrastructure, taking down 106 servers and cleaning ~14,971 WordPress sites used to serve fake-update malware. U.S. CISA added a critical Splunk Enterprise flaw (CVE-2026-20253, CVSS 9.8) to its Known Exploited Vulnerabilities catalog. Major data exposures and campaigns were disclosed, including a 24 billion‑record credential leak, a leak of membership/login data from Peter Thiel’s Dialog site, and a Tor‑based clipper campaign targeting crypto‑se

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
ce269c4b688f23421cb92f8c51a7fd8897586af829a06da1763d6f3505d490ef
Enrichment time
2026-06-20T02:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.