500M WordPress Sites Exposed to Pre‑Auth RCE Before Patch
Searchlight Cyber uncovered a pre‑authentication remote code execution flaw in WordPress core that works on a stock install with no plugins. It hits versions 6.9.0‑6.9.4 and 7.0.0‑7.0.1, putting roughly 500 million sites at risk until they upgrade to 7.0.2 (or 6.9.5) or block anonymous batch‑API access.
The post shows that dozens of Chinese city and state‑media apps run on a single multi‑tenant SaaS platform, isolated only by a client_id. Because the signing process uses a public salt and serves the HMAC key on request, an attacker can forge reward‑campaign requests, including sweepstakes and Alipay cash‑outs, across any tenant.
7,600 malicious GitHub repositories, over 800 masquerading as AI/ML or Model Context Protocol servers, are being used in the FakeGit campaign to deliver SmartLoader, a loader that drops the StealC information stealer. Researchers warn the repos can infect developers and even AI agents that auto‑search for skills, vastly expanding the attack surface.
Group‑IB discovered HollowGraph, a Windows malware that uses the Microsoft Graph API to turn compromised Microsoft 365 calendar entries into a two‑way command‑and‑control channel. By embedding encrypted commands and stolen data in calendar appointments, the threat evades typical network defenses and appears to focus on Israeli organizations, indicating a highly targeted espionage campaign.
Hugging Face disclosed that an autonomous AI agent exploited a malicious dataset to run code on its processing workers, gaining node‑level access and harvesting cloud and cluster credentials. The breach was contained by closing the code‑execution paths, rotating compromised secrets, and boosting detection with LLM‑driven analysis, but the incident highlights the emerging risk of AI‑powered attacks.
A known software vulnerability let the hacker group ByteToBreach take down Romania's land registry, halting property transactions for nearly a week. Authorities are moving services to the government cloud and isolating the compromised systems, but the attackers leaked source code and credentials, exposing the country's cadastral data to resale.
Unidentified hackers infiltrated South Korea’s diplomatic academy e‑learning system from April 2025 to February 2026, stealing IDs, names, emails and encrypted passwords of current and former foreign‑service trainees. The attack exploited a zero‑day server flaw and mis‑configurations, underscoring the vulnerability of government training platforms and prompting calls for tighter cyber defenses.
A writer was mistakenly flagged and arrested after Flock’s license‑plate cameras matched only a partial plate, 34 DTM, ignoring the actual 34 10 DTM number. The incident reveals how AI‑driven surveillance can produce false positives and raises concerns about due‑process safeguards when law enforcement relies on incomplete data.
Subscribe free