⤷ Title: Operation Endgame Takes Down SocGholish, Amadey, and StealC Malware
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 02:09:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amadey #Europol #Evil Corp #malware takedown #Operation Endgame #SocGholish #StealC #wordpress security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 25 Jun 2026 02:09:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Amadey #Europol #Evil Corp #malware takedown #Operation Endgame #SocGholish #StealC #wordpress security
Daily CyberSecurity
Operation Endgame Takes Down SocGholish, Amadey, and StealC Malware
Operation Endgame disrupts the SocGholish malware network, seizing EUR 41M in crypto and 326 servers. WordPress site owners must act now.
⤷ Title: New Critical Zero-Auth Vulnerability in WordPress YMC Filter: CVE-2026–10823
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 05:26:00 GMT
════════════════════════
⌗ Tags: #wordpress_security #cybersecurity #wordpress_vulnerabilities #infosec #cve_2026_10823
════════════════════════
𐀪 Author: Synthex
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 05:26:00 GMT
════════════════════════
⌗ Tags: #wordpress_security #cybersecurity #wordpress_vulnerabilities #infosec #cve_2026_10823
Medium
New Critical Zero-Auth Vulnerability in WordPress YMC Filter: CVE-2026–10823
The WordPress ecosystem thrives on modular flexibility, but peripheral plugins often introduce unintended paths of least resistance for…
⤷ Title: CVE-2026–10083: Unauthenticated Stored XSS in APCu Manager via Cache Key Pollution
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 13:01:03 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #xs #wordpress_security #cve
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Wed, 01 Jul 2026 13:01:03 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #xs #wordpress_security #cve
Medium
CVE-2026–10083: Unauthenticated Stored XSS in APCu Manager via Cache Key Pollution
When object-cache keys become an attack surface
⤷ Title: CVE-2026–10091: Stored XSS in Email JavaScript Cloak WordPress Plugin
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #wordpress_security #xs #wordpress_security_plugin #security_plugin #cve
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #wordpress_security #xs #wordpress_security_plugin #security_plugin #cve
Medium
CVE-2026–10091: Stored XSS in Email JavaScript Cloak WordPress Plugin
When a simple shortcode becomes a persistent script injection vector
⤷ Title: CVE-2026–10092: Unauthenticated Stored XSS in Cincopa Video and Media Plug-in
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #security_plugin #wordpress_security_plugin #wordpress_security #cve #xs
════════════════════════
𐀪 Author: CyberPodcast
════════════════════════
ⴵ Time: Sun, 05 Jul 2026 13:01:01 GMT
════════════════════════
⌗ Tags: #security_plugin #wordpress_security_plugin #wordpress_security #cve #xs
Medium
CVE-2026–10092: Unauthenticated Stored XSS in Cincopa Video and Media Plug-in
When WordPress comments become a persistent shortcode execution surface
⤷ Title: WordPress Sites at Risk: Outdated PHP, Plugins, and Default Configs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 03:53:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #censys #End_of_Life Software #MR.GREEN Hack #Outdated PHP #wordpress security #xmlrpc.php #Yoast SEO
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 08 Jul 2026 03:53:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #censys #End_of_Life Software #MR.GREEN Hack #Outdated PHP #wordpress security #xmlrpc.php #Yoast SEO
Daily CyberSecurity
WordPress Sites at Risk: Outdated PHP, Plugins, and Default Configs
Hundreds of WordPress sites remain easy targets year after year. The cause is rarely a rare zero-day vulnerability. Instead, it is outdated PHP versions, forgotten plugins, and default configurati…
⤷ Title: Breaking Into Internal: Enumeration, Exploitation & Privilege Escalation
════════════════════════
𐀪 Author: Mohamed Sameh
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 05:11:22 GMT
════════════════════════
⌗ Tags: #wordpress_security #penetration_testing #cybersecurity #tryhackme #privilege_escalation
════════════════════════
𐀪 Author: Mohamed Sameh
════════════════════════
ⴵ Time: Sat, 18 Jul 2026 05:11:22 GMT
════════════════════════
⌗ Tags: #wordpress_security #penetration_testing #cybersecurity #tryhackme #privilege_escalation
Medium
Breaking Into Internal: Enumeration, Exploitation & Privilege Escalation
Challenge URL : https://tryhackme.com/room/internal
⤷ Title: wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 01:49:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60137 #CVE_2026_63030 #Pre_Auth RCE #REST API batch #webshell #WordPress Core RCE #wordpress security #wp2shell exploit
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 01:49:52 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_60137 #CVE_2026_63030 #Pre_Auth RCE #REST API batch #webshell #WordPress Core RCE #wordpress security #wp2shell exploit
Daily CyberSecurity
wp2shell: WordPress Core RCE Exploited in the Wild as Public PoC Code Circulates
Attackers are already dropping webshells on WordPress sites through a flaw in WordPress Core itself. The bug chain, named wp2shell, delivers an unauthenticated WordPress Core RCE. No plugin, no th…
⤷ Title: Understanding the WordPress wp2shell Attack
════════════════════════
𐀪 Author: Hitakshi Parmar
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 08:03:33 GMT
════════════════════════
⌗ Tags: #wordpress_security #vulnerability_management #cybersecurity #threat_analysis #ethical_hacking
════════════════════════
𐀪 Author: Hitakshi Parmar
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 08:03:33 GMT
════════════════════════
⌗ Tags: #wordpress_security #vulnerability_management #cybersecurity #threat_analysis #ethical_hacking
Medium
Understanding the WordPress wp2shell Attack
Cybersecurity is constantly evolving, and attackers are always looking for new ways to exploit software vulnerabilities. One recent example…
⤷ Title: CVE Weekly Roundup: July 27 – August 2, 2026
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 01:57:54 +0000
════════════════════════
⌗ Tags: #Weekly Recap #Apache Traffic Server #CISA KEV #Cisco FMC #CVE Roundup #Fortinet #VeloCloud #Weekly Report #wordpress security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 01:57:54 +0000
════════════════════════
⌗ Tags: #Weekly Recap #Apache Traffic Server #CISA KEV #Cisco FMC #CVE Roundup #Fortinet #VeloCloud #Weekly Report #wordpress security
Daily CyberSecurity
CVE Weekly Roundup: July 27 – August 2, 2026
The CVE WATCHTOWER logged 2,077 new vulnerabilities between July 27 and August 2, 2026. This CVE weekly roundup breaks down the numbers, flags what is under active attack, and highlights the entri…
⤷ Title: BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 09 Aug 2026 00:37:56 +0000
════════════════════════
⌗ Tags: #Malware #BdThemes #supply chain attack #Wordfence #wordpress security #XSS
Daily CyberSecurity
BdThemes Supply Chain Attack Poisons Plugin API to Hijack WordPress Admins
At a Glance Malware family API-driven XSS supply chain implant (Biggopti banner abuse) Threat actor Suspected; linked to the ARVE and OptinMonster campaigns Targets WordPress sites running seven B…