New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

2026-07-18T01:24:11Z5e69b33ef12808b2a17ceceddd76cc0161263b3ff5e96560f24abee729718230
acrs-tealerblockchain-c2botnetchainveilcisa-kevclickfixclicklock-macos-stealer','n8n-token-exchange','agent-data-injurycloud-credentialscode-signingdenial-of-servicedigiCerthollowbytenadmeshnpmopensslratsharepointsteganographysupply-chainsvg-steganographytelepuzvitevenomwordpresswp2shellzoom

What happened

This collection highlights multiple high-impact vulnerabilities, active malware campaigns, and supply-chain attacks. Key issues: a WordPress core unauthenticated RCE dubbed “wp2shell” (affecting 6.9/7.0 until forced updates landed); OpenSSL “HollowByte” denial-of-service via an 11‑byte TLS request (no CVE published); a Vite/npm supply‑chain campaign (ViteVenom/ChainVeil) delivering a RAT via blockchain-based C2; NadMesh Go botnet scanning exposed AI services to harvest cloud keys and Kubernetes tokens; DigiCert code‑signing certificate theft tied to a GoldenEyeDog subgroup; and resurfacing ofь

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5e69b33ef12808b2a17ceceddd76cc0161263b3ff5e96560f24abee729718230
Enrichment time
2026-07-18T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.