logo

WordPress, AI Platform, Proxy Supply-Chain Compromises: Backdoors and Cross-Tenant Leaks

ID: 4fdcbcbd-bfaf-5771-b2fe-cab3969de601

STIX ID: report--4fdcbcbd-bfaf-5771-b2fe-cab3969de601

Feed Name: defend.network

Threat Score
78/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

...
...

This briefing details several high-severity threats: a supply-chain backdoor in ShapedPlugin WordPress Pro plugins, Dify platform flaws allowing cross-tenant exposure of AI conversation data, a 29‑year‑old Squid proxy heap over‑read (Squidbleed) that can leak HTTP credentials, an active OXLOADER/CastleStealer campaign targeting cryptocurrency users, and exploitation of Meta’s AI support bot to reset Instagram accounts; immediate actions recommended include patching, secrets rotation, auditing affected systems, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.