Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

2026-06-20T19:24:11Z763484b455355f6d34ff5c97aa29caf170fae12eda9559076b86887b7b43a592
agent-browsing-rceapi-keysapple-a12-a13autojackcisaedr-killersf5gentlekillergentlemen-raasgravity-smtpinformation-disclosurejcejoomlamastranginxnpmoauth-abuseoauth-tokensraassalesforce-kluesecureromsupply-chainunpatchable-hardware-bugusbliter8wordpress

What happened

This collection of The Hacker News stories highlights multiple active and high-impact threats across ecosystems: an information-disclosure exploit targeting the Gravity SMTP WordPress plugin (CVE-2026-4020) used to extract API keys and secrets; an unpatchable SecureROM exploit (usbliter8) affecting Apple A12/A13 devices; critical remote-code-execution flaws in NGINX (including CVE-2026-42530) and a maximum-severity Joomla JCE flaw (CVE-2026-48907) with evidence of active exploitation; a Microsoft Defender privilege-escalation zero-day (CVE-2026-50656); and other incidents including FortiGate (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
763484b455355f6d34ff5c97aa29caf170fae12eda9559076b86887b7b43a592
Enrichment time
2026-06-20T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.