New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
2026-07-18T13:24:06Z•95354657f63a07a6ad71050a99c02ffdaafc2f6a411175334a5d00a1c02900bc
acr-stealerblockchain-c2botnetclickfixclicklockcloud-credentialscode-signingdigicertgoldeneyedoghollowbytekubernetesmacos-stealernadmeshnpmopensslottercookieratsharepointstealthy-steganographysupply-chainsvg-steganographytelepuzvitewordpresswp2shell
What happened
A broad set of high-impact security stories: a WordPress core RCE (wp2shell) allows unauthenticated code execution on bare installs; OpenSSL HollowByte enables memory-exhaustion DoS via 11-byte TLS requests; a cluster of malicious Vite npm packages (ViteVenom) use a blockchain-based C2 to deliver a RAT; NadMesh botnet scans exposed AI services to harvest cloud keys and Kubernetes tokens; a DigiCert incident involved theft of code-signing certificates tied to a GoldenEyeDog subgroup; multiple ClickFix-based campaigns and new stealers (ACR Stealer, TELEPUZ, ClickLock) are actively exfiltratingブラ
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 95354657f63a07a6ad71050a99c02ffdaafc2f6a411175334a5d00a1c02900bc
- Enrichment time
- 2026-07-18T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.