WordPress, SonicWall zero-days in active exploitation; FakeGit malware campaign hits 7,600 GitHub repos
ID: f288a267-a055-57e4-88a1-8aeb7930a75b
STIX ID: report--f288a267-a055-57e4-88a1-8aeb7930a75b
Feed Name: defend.network
**Executive summary:** Multiple high-severity threats are active: a FakeGit campaign weaponizing ~7,600 GitHub repositories to distribute SmartLoader; chained WordPress zero-days (CVE-2026-60137 / CVE-2026-63030) exploited within days of disclosure; SonicWall SMA1000 zero-days exploited for weeks by actor UTA0533 to deploy custom malware; HollowGraph malware using Microsoft 365 calendars for C2 and exfiltration; and an Estée Lauder breach via an Oracle E-Business Suite vulnerability — urgent patching, repository audits, credential rotations, and log reviews are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
