New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

2026-07-19T01:24:19Zb2aedc94aba97cacc6f9aead2a304c41cac0de822a238c968c17f0373c318de4
acr-stealeragent-data-injectionblockchain-c2botnetclickfixclicklockcode-signingcve-2026-53412cve-2026-58644daxin","gpt-reddigicerthollowbyten8nnadmeshnpmopensslprompt-injectionratsharepointsupply-chaintelepuzvitewordpresswp2shellzoom

What happened

A burst of high-impact security stories: an unauthenticated WordPress core RCE (wp2shell) was disclosed and assigned CVEs; OpenSSL’s "HollowByte" bug enables small TLS requests to reserve memory and cause DoS; a supply-chain campaign (malicious Vite npm packages) uses a four-tier blockchain C2 to deliver a RAT; and a new NadMesh botnet is harvesting exposed AI services and thousands of AWS keys. Multiple ClickFix-based delivery campaigns (ACR Stealer, TELEPUZ) and a ClickLock macOS stealer are stealing credentials and data. CISA added SharePoint RCE CVE-2026-58644 to KEV (critical, CVSS 9.8),/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b2aedc94aba97cacc6f9aead2a304c41cac0de822a238c968c17f0373c318de4
Enrichment time
2026-07-19T01:24:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.