New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

2026-07-19T07:24:06Z700c95629b0a3fb7a26a756ec64e7b316c95174322143df765c5fa6d7c200c8a
ACR-StealerCISA-KEVClickLockOtterCookieSharePointTELEPUZViteVenomblockchain-C2cloud-keyscode-signingdigicerthollowbytekubernetesmalwaren8nnadmeshnpmopensslratstealthy-steganographysupply-chaintoken-exchangevitewordpresswp2shell

What happened

Multiple high-impact vulnerabilities and active malware campaigns were reported. Notable items: an unauthenticated WordPress core RCE (wp2shell) with published mechanism and PoC; an OpenSSL denial-of-service (HollowByte) that can exhaust server memory; a cluster of malicious Vite npm packages using a blockchain-based C2 (ViteVenom) delivering a RAT; NadMesh botnet harvesting exposed AI services for AWS keys and Kubernetes tokens; a DigiCert incident tied to a GoldenEyeDog subgroup and theft of code‑signing certificates; multiple infostealers and droppers (ACR Stealer, TELEPUZ, ClickLock) using

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
700c95629b0a3fb7a26a756ec64e7b316c95174322143df765c5fa6d7c200c8a
Enrichment time
2026-07-19T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code · Baitaphish