ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

2026-06-23T01:24:08Z27d1e836f0e7b32dea6de2dd38680c0739f4e0c7d5d937664c19d86432dc0721
ai-securityapple-a12-a13backdoorcastleStealeredr-evasionfortibleedfortinetgentlekillergoogle-adsheap-overreadinformation-disclosuremalvertisingmalware-loadermulti-tenant-data-exposurenginxraasransomwarerceremote-code-executionsecureromsquidsquidbleedsupply-chainunpatchable-exploitwordpress

What happened

A batch of high-impact cyber incidents and vulnerabilities were reported: ShapedPlugin's WordPress Pro plugins were backdoored via a supply-chain compromise of the vendor build/distribution pipeline; DifyTap (four flaws in the Dify agentic workflow platform) can allow cross-tenant AI chat disclosure; a 29-year-old Squid heap over-read dubbed “Squidbleed” can leak cleartext HTTP requests (including credentials/tokens); a new OXLOADER campaign uses malicious Google Ads to deliver CastleStealer; an unpatchable SecureROM exploit (usbliter8) affects Apple A12/A13 devices; Microsoft and others warn‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
27d1e836f0e7b32dea6de2dd38680c0739f4e0c7d5d937664c19d86432dc0721
Enrichment time
2026-06-23T01:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.