New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
2026-07-19T01:24:19Z•b2aedc94aba97cacc6f9aead2a304c41cac0de822a238c968c17f0373c318de4
acr-stealeragent-data-injectionblockchain-c2botnetclickfixclicklockcode-signingcve-2026-53412cve-2026-58644daxin","gpt-reddigicerthollowbyten8nnadmeshnpmopensslprompt-injectionratsharepointsupply-chaintelepuzvitewordpresswp2shellzoom
What happened
A burst of high-impact security stories: an unauthenticated WordPress core RCE (wp2shell) was disclosed and assigned CVEs; OpenSSL’s "HollowByte" bug enables small TLS requests to reserve memory and cause DoS; a supply-chain campaign (malicious Vite npm packages) uses a four-tier blockchain C2 to deliver a RAT; and a new NadMesh botnet is harvesting exposed AI services and thousands of AWS keys. Multiple ClickFix-based delivery campaigns (ACR Stealer, TELEPUZ) and a ClickLock macOS stealer are stealing credentials and data. CISA added SharePoint RCE CVE-2026-58644 to KEV (critical, CVSS 9.8),/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b2aedc94aba97cacc6f9aead2a304c41cac0de822a238c968c17f0373c318de4
- Enrichment time
- 2026-07-19T01:24:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.