Critical Exploits: npm Supply Chain, WordPress Plugin, SolarWinds, IIS Attacks
ID: 8d3b51aa-2dac-5916-9bca-3e205decf4ef
STIX ID: report--8d3b51aa-2dac-5916-9bca-3e205decf4ef
Feed Name: defend.network – Daily Threat Briefings
**Executive Summary:** Critical, multi-vector active threats reported: npm supply-chain poisoning distributing the IronWorm credential stealer and a Miasma worm variant; Everest Forms Pro (CVE-2026-3300, CVSS 9.8) actively exploited for remote code execution across ~4,000 WordPress installs; SolarWinds Serv-U being exploited for denial-of-service; OP-512 targeting IIS with custom web shells; and over 900 internet-exposed automatic tank gauge (ATG) systems under attack — immediate patching, dependency audits, credential rotation, and isolation/segmentation are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
