TCSR Weekly Roundup: Critical WordPress Exploits, SonicWall Zero-Days, and Supply Chain Risks
This week's TCSR roundup covers critical WordPress and NGINX flaws, SonicWall zero-days exploited by ransomware, and supply chain attacks on Hugging Face.
Welcome to the Talivio Cyber Security Report (TCSR) weekly roundup. This week, we analyze a series of critical vulnerabilities in core web technologies, active zero-day exploitation targeting network gateways, and emerging threats leveraging automated AI systems and developer repositories.
Critical Vulnerabilities in WordPress Core and NGINX
A critical remote code execution (RCE) vulnerability in WordPress Core, tracked as CVE-2026-63030 (associated with "wp2shell"), is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute arbitrary code on vulnerable sites, prompting urgent calls for administrators to patch their installations.
Simultaneously, a critical NGINX vulnerability has been disclosed that can crash worker processes and potentially allow remote code execution. Because NGINX and WordPress power a vast portion of the web, securing these assets is paramount.
SonicWall Zero-Days and Industrial Ransomware Disruptions
Edge security devices remain a primary target for ransomware groups. Threat actors, specifically associated with Inc Ransomware, exploited zero-day vulnerabilities in SonicWall SMA appliances to gain root access prior to public disclosure and patching.
The real-world impact of these and similar network intrusions was highlighted this week as dairy producer Fairlife, a unit of Coca-Cola, was forced to temporarily suspend production at a US facility following a cyber incident. Additionally, medical device manufacturer Abbott announced it is investigating two separate cyber incidents amid extortion claims.
Supply Chain and AI Repository Threats
The security of developer environments and AI platforms is facing increased scrutiny. Hugging Face, the prominent AI model repository, was reportedly breached by an autonomous AI agent, underscoring emerging risks as organizations place "blind trust" in AI systems.
Traditional software supply chains also face ongoing threats. A campaign dubbed "SleeperGem" successfully targeted developer machines by distributing three malicious packages via the RubyGems repository.
Evolving Malware Delivery and Utility Exploits
Attackers continue to refine their delivery methods and target common utility software:
- 7-Zip Patched: A remote code execution vulnerability in the popular 7-Zip archiving utility was resolved. The flaw could be triggered simply by opening a specially crafted malicious archive.
- ACR Stealer Surge: Microsoft issued a warning regarding a significant spike in ACR Stealer malware attacks targeting its customers.
- ClickFix CAPTCHAs: The threat group UAC-0145 has been observed using highly deceptive "ClickFix" CAPTCHAs to trick users into executing commands that infect Ukrainian devices with malware.
- Software Abuse: Elsewhere, attackers have been abusing ViPNet software to target Russian government agencies.
What This Means for You
The active exploitation of WordPress, NGINX, and SonicWall appliances emphasizes that perimeter security must be continuously monitored. Organizations should immediately audit their external attack surface for outdated software versions and exposed administrative interfaces. Regularly scanning your systems for known CVEs, verifying SSL/TLS configurations, and ensuring that public-facing headers do not expose sensitive environment details are critical steps in preventing unauthorized access before patches can be deployed.
Sources
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent — The Hacker News
- WP2Shell WordPress Vulnerabilities Exploited in the Wild — SecurityWeek
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — The Hacker News
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — The Hacker News
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — The Hacker News
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — The Hacker News
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives — BleepingComputer
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now — BleepingComputer
- Microsoft warns of surge in ACR Stealer attacks on customers — BleepingComputer