New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
2026-07-18T19:24:05Z•07c66699219c397fa0c5b888cbc440bbd6bf053a28cf1365cf2c36acd8a8b3cb
CISA-KEVDaxinDigiCertNadMeshOtterCookieRATSharePointZoomauth-bypassblockchain-C2botnetcloud-credentialscode-signingdenial-of-servicehollowbytekubernetesmacOS-stealern8nnpmopensslsteganographysupply-chainvitewordpresswp2shell
What happened
The feed aggregates multiple high-impact security stories: a new WordPress core vulnerability cluster dubbed "wp2shell" allows unauthenticated remote code execution on vanilla installs of WordPress (affects 6.9/7.0; PoC and CVEs published); OpenSSL "HollowByte" is a denial-of-service that uses an 11‑byte TLS request to make servers reserve up to ~131 KB per connection until process restart (fix shipped without a CVE); a supply‑chain campaign (ViteVenom) uses seven malicious Vite npm packages with a blockchain-based multi‑tier C2 to deliver a RAT; NadMesh botnet is scanning exposed AI services/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 07c66699219c397fa0c5b888cbc440bbd6bf053a28cf1365cf2c36acd8a8b3cb
- Enrichment time
- 2026-07-18T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.