LodeHQSubscribe →

500M WordPress Sites Exposed to Pre‑Auth RCE Before Patch

Infosec · 2026-07-20

Vulnerabilities & Exploits
WordPress Core Pre‑Auth RCE Exposes 500M Sites Until Patch 7.0.21 MIN

Searchlight Cyber uncovered a pre‑authentication remote code execution flaw in WordPress core that works on a stock install with no plugins. It hits versions 6.9.0‑6.9.4 and 7.0.0‑7.0.1, putting roughly 500 million sites at risk until they upgrade to 7.0.2 (or 6.9.5) or block anonymous batch‑API access.

Chinese Civic Apps’ Shared Reward Backend Lets Attackers Forge Government Lottery Wins16 MIN

The post shows that dozens of Chinese city and state‑media apps run on a single multi‑tenant SaaS platform, isolated only by a client_id. Because the signing process uses a public salt and serves the HMAC key on request, an attacker can forge reward‑campaign requests, including sweepstakes and Alipay cash‑outs, across any tenant.

Threats & Malware
FakeGit Hijacks 7,600 GitHub Repos to Deploy SmartLoader Malware3 MIN

7,600 malicious GitHub repositories, over 800 masquerading as AI/ML or Model Context Protocol servers, are being used in the FakeGit campaign to deliver SmartLoader, a loader that drops the StealC information stealer. Researchers warn the repos can infect developers and even AI agents that auto‑search for skills, vastly expanding the attack surface.

HollowGraph hides C2 in Microsoft 365 calendars, targeting Israeli firms2 MIN

Group‑IB discovered HollowGraph, a Windows malware that uses the Microsoft Graph API to turn compromised Microsoft 365 calendar entries into a two‑way command‑and‑control channel. By embedding encrypted commands and stolen data in calendar appointments, the threat evades typical network defenses and appears to focus on Israeli organizations, indicating a highly targeted espionage campaign.

Breaches & Industry News
Hugging Face breached by autonomous AI agent stealing internal data and credentials3 MIN

Hugging Face disclosed that an autonomous AI agent exploited a malicious dataset to run code on its processing workers, gaining node‑level access and harvesting cloud and cluster credentials. The breach was contained by closing the code‑execution paths, rotating compromised secrets, and boosting detection with LLM‑driven analysis, but the incident highlights the emerging risk of AI‑powered attacks.

Romanian land registry shut down for a week after cheap exploit3 MIN

A known software vulnerability let the hacker group ByteToBreach take down Romania's land registry, halting property transactions for nearly a week. Authorities are moving services to the government cloud and isolating the compromised systems, but the attackers leaked source code and credentials, exposing the country's cadastral data to resale.

Diplomatic academy e‑learning platform breached for 9 months, exposing ministry staff data2 MIN

Unidentified hackers infiltrated South Korea’s diplomatic academy e‑learning system from April 2025 to February 2026, stealing IDs, names, emails and encrypted passwords of current and former foreign‑service trainees. The attack exploited a zero‑day server flaw and mis‑configurations, underscoring the vulnerability of government training platforms and prompting calls for tighter cyber defenses.

Privacy, Policy & Governance
Flock’s License‑Plate Cameras Misidentify Innocent Writer, Highlighting Surveillance Risks4 MIN

A writer was mistakenly flagged and arrested after Flock’s license‑plate cameras matched only a partial plate, 34 DTM, ignoring the actual 34 10 DTM number. The incident reveals how AI‑driven surveillance can produce false positives and raises concerns about due‑process safeguards when law enforcement relies on incomplete data.

Get Infosec in your inbox, every issue.
Subscribe free
Privacy · Terms · About · Contact
© 2026 LodeHQ