Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026–63030 and CVE-2026–60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.

The critical exploit chain abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.

Although the technical details were not released, proof-of-concept exploits started to emerge over the weekend, shortly after threat intelligence and cyber risk management company SearchLight Cyber disclosed the wp2shell security issue.

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.

During the operation, authorities seized more than 200 servers, effectively disrupting the malicious service and rendering it inoperable.

The action was led by Frankfurt’s Prosecutor General Office (ZIT), Germany’s Federal police (BKA), which worked in collaboration with U.S. law enforcement agencies.

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A large-scale operation dubbed ‘FakeGit’ is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million downloads.

Over 800 repositories pretended to be AI skills or MCP servers and appeared more than 600 times in public AI registries and catalogs. This increased the likelihood of being discovered by AI agents and developers, a technique that researchers call “agentbaiting.”

The campaign is considered a continuation of an older operation that used Lumma Stealer and was attributed to a threat actor tracked as “Water Kurita” by researchers at cybersecurity company Trend Micro.

/* */