Attackers exploit Marimo CVE-2026–39987, with one human operator pivoting to an SSH bastion in eight seconds after initial access.
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current.
The attack requires an attacker who already controls the server’s software and can briefly access the machine to insert a small circuit board, called an interposer, between the processor and a memory module.
The interposer costs under $200 to build. DDRop works against Intel TDX, Intel Scalable SGX, and AMD SEV-SNP, the hardware that cloud services use to keep customer data private while it is in use, even from the cloud provider.
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account.
Developer Janis Elsts says an unauthorized party accessed the adminmenueditor.com website on Monday and uploaded version 2.35 as an update for the plugin’s Pro version. The update included an includes/wp-user-consent.php file that installed a web shell on affected websites.
After noticing the intrusion, Elsts removed the malicious update and pushed a clean version 2.36 on the same day at 19:00 UTC. However, the hacker still had access to the website and compromised the new version, too.
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
The flaw is tracked as CVE-2026–27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus.
An attacker can exploit it to upload PHP webshells and execute code, potentially leading to a complete site compromise.
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update.
This follows a wave of customer reports on Reddit and the Microsoft Q&A forums that the KB5002914 Office security update is breaking copy-and-paste, autofill, and formula dragging in Excel.
“Although users try to paste content, the source remains selected and the destination is unmodified,” Microsoft said in an updated support document confirming these issues.
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month’s security updates, along with Hyper-V and USB audio problems on some Windows versions.
The September 2026 security updates caused Remote Desktop Services (RDS) to become unstable on affected systems, leading to RDP connection and sign-in failures and, in some cases, unresponsive servers.
Microsoft previously acknowledged the issue after Windows administrators reported widespread RDS problems following the September updates.