BdThemes Plugins Installed Backdoors Through a Poisoned API
Seven BdThemes WordPress plugins loaded a poisoned remote feed that created rogue admins and hidden webshells. Check the exact indicators and recover safely.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
October 4, 2026
Seven BdThemes WordPress plugins loaded a poisoned remote feed that created rogue admins and hidden webshells. Check the exact indicators and recover safely.
PortSwigger research shows how sanitized CSS in webmail can cross the message boundary, spoof login forms, and capture passwords. Learn the exposure levels and…
Golden Gh0st uses a separate loader to launch a modular remote-access Trojan. Learn how to isolate a suspected device, preserve evidence, revoke sessions, and…
Vanta Stealer may target browser sessions, gaming and messaging accounts, wallet data, and local documents. Follow the safe order to isolate, clean, revoke sessions,…
Unit 42 says criminals added stolen AI API keys to gray-market proxy services within minutes, creating nearly $1 million in charges. Learn the warning…
ENDLESSDOORS is embedded in firmware for 20 tested Zbtlink and Wiflyer router models. Check the model, isolate the device, and plan replacement.
GitGuardian found 321 reachable n8n instances still accepting API tokens leaked in public GitHub commits. Revoke exposed keys, audit workflows and executions, and rotate…
See what is verified about WARDEN Stealer, how cookies, passwords, wallets, and clipboard data may be exposed, and what to do after a suspected…
The Keyv npm worm poisoned hundreds of packages and can react when a stolen GitHub token is revoked. Check persistence first, then rotate credentials…