New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
2026-07-18T01:24:11Z•5e69b33ef12808b2a17ceceddd76cc0161263b3ff5e96560f24abee729718230
acrs-tealerblockchain-c2botnetchainveilcisa-kevclickfixclicklock-macos-stealer','n8n-token-exchange','agent-data-injurycloud-credentialscode-signingdenial-of-servicedigiCerthollowbytenadmeshnpmopensslratsharepointsteganographysupply-chainsvg-steganographytelepuzvitevenomwordpresswp2shellzoom
What happened
This collection highlights multiple high-impact vulnerabilities, active malware campaigns, and supply-chain attacks. Key issues: a WordPress core unauthenticated RCE dubbed “wp2shell” (affecting 6.9/7.0 until forced updates landed); OpenSSL “HollowByte” denial-of-service via an 11‑byte TLS request (no CVE published); a Vite/npm supply‑chain campaign (ViteVenom/ChainVeil) delivering a RAT via blockchain-based C2; NadMesh Go botnet scanning exposed AI services to harvest cloud keys and Kubernetes tokens; DigiCert code‑signing certificate theft tied to a GoldenEyeDog subgroup; and resurfacing ofь
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5e69b33ef12808b2a17ceceddd76cc0161263b3ff5e96560f24abee729718230
- Enrichment time
- 2026-07-18T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.