WordPress, AI Platform, Proxy Supply-Chain Compromises: Backdoors and Cross-Tenant Leaks
ID: 4fdcbcbd-bfaf-5771-b2fe-cab3969de601
STIX ID: report--4fdcbcbd-bfaf-5771-b2fe-cab3969de601
Feed Name: defend.network
This briefing details several high-severity threats: a supply-chain backdoor in ShapedPlugin WordPress Pro plugins, Dify platform flaws allowing cross-tenant exposure of AI conversation data, a 29‑year‑old Squid proxy heap over‑read (Squidbleed) that can leak HTTP credentials, an active OXLOADER/CastleStealer campaign targeting cryptocurrency users, and exploitation of Meta’s AI support bot to reset Instagram accounts; immediate actions recommended include patching, secrets rotation, auditing affected systems, and enforcing MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
