WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw
 
This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.
 
Hugging Face’s disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.
 
Arctic Wolf’s report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.
 
EY client tax-data exposure via a third-party platform.
 
00:00 Top Stories Teaser
00:28 WP2Shell WordPress Frenzy
02:58 AI Agent Hacks Hugging Face
05:16 Killin Hits Palo Alto VPNs
07:33 Craneware Healthcare Breach
09:15 EY Third Party Data Leak
10:47 Wrap Up and Sign Off

This article has been indexed from Cybersecurity Today

Read the original article: