TCSR Weekly Roundup: Critical WordPress Flaw, SonicWall Zero-Days, and Supply Chain Risks
This week's TCSR roundup covers a critical WordPress core vulnerability, SonicWall zero-days, supply chain threats, and major ransomware disruptions.
Welcome to this week's Talivio Cyber Security Report (TCSR) news roundup. In this edition, we analyze several high-impact security developments, including a critical WordPress core vulnerability actively exploited in the wild, zero-day exploits targeting SonicWall appliances, supply chain campaigns targeting developers, and major operational disruptions in the consumer goods and healthcare sectors.
WordPress Core Under Active Attack (wp2shell)
A critical Remote Code Execution (RCE) vulnerability in WordPress Core, tracked as CVE-2026-63030 and dubbed "wp2shell", is being actively exploited in the wild. The flaw allows unauthenticated attackers to run arbitrary code on affected servers. With public exploits now widely available, immediate patching is highly recommended for all WordPress administrators to prevent complete site takeover.
TCSR Note: Keeping content management systems updated is vital. Automated scanning of your external perimeter can help identify exposed platforms, outdated CMS versions, and unpatched CVEs before attackers do.
Critical Flaws Hit NGINX, SonicWall, and 7-Zip
Infrastructure security faced significant challenges this week with multiple critical vulnerabilities. SonicWall SMA zero-days were actively exploited by the Inc Ransomware group to gain root access before details were publicly disclosed. Meanwhile, a critical vulnerability in NGINX could allow attackers to crash worker processes or potentially execute remote code. Additionally, a newly patched flaw in the 7-Zip file archiver could lead to RCE when processing malicious archives, highlighting the need for prompt software updates.
TCSR Note: Regularly scanning network perimeters for unpatched CVEs and securing edge devices like VPNs and firewalls is essential to block these entry points.
Supply Chain and Developer Targets
Developers and AI repositories are increasingly in the crosshairs of sophisticated threat actors. Hugging Face, the world's largest AI model repository, was recently breached by an autonomous AI agent, highlighting emerging risks in AI ecosystems. Meanwhile, a malicious campaign named "SleeperGem" was discovered using three compromised RubyGems packages to target developer machines. These incidents underscore the growing risk of blind trust in third-party software libraries and autonomous AI tools.
Ransomware Disrupts Production and Operations
Real-world operations continue to feel the impact of cyberattacks. Dairy producer Fairlife, a unit of Coca-Cola, was forced to suspend production at a US facility following a ransomware attack. In the healthcare sector, Abbott is investigating two separate cyber incidents following extortion claims from threat actors, emphasizing the persistent threat ransomware poses to critical supply chains and business continuity.
Sophisticated Malware Campaigns on the Rise
Threat actors are deploying creative delivery methods to bypass traditional defenses. Microsoft issued a warning regarding a surge in ACR Stealer malware targeting its customers. In Ukraine, the threat group UAC-0145 is using deceptive "ClickFix" CAPTCHA prompts to trick users into executing malware. Additionally, macOS users are facing threats from "CrashStealer" malware, proving that no operating system is exempt from targeted campaigns.
What This Means for You
This week's developments highlight that threat actors are moving quickly to exploit newly discovered vulnerabilities in core web technologies like WordPress and NGINX, while also targeting critical infrastructure through zero-days. To protect your organization, ensure all external-facing software is promptly patched, monitor developer dependencies, and verify that your external attack surface is thoroughly mapped. Regular vulnerability scanning, TLS configuration checks, and monitoring for exposed files remain your first line of defense.
Sources
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent — The Hacker News
- WP2Shell WordPress Vulnerabilities Exploited in the Wild — SecurityWeek
- SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — The Hacker News
- Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — The Hacker News
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — The Hacker News
- SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access — The Hacker News
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives — BleepingComputer
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now — BleepingComputer
- Microsoft warns of surge in ACR Stealer attacks on customers — BleepingComputer