Attackers have moved beyond scanning for WordPress sites vulnerable to CVE-2026-87902. They are now exploiting the flaw to plant files that run shell commands when they are accessed, according to WordPress security firm Patchstack.
The vulnerability was fixed in WordPress 7.1.2. Scanning began less than five hours after that release. Since then, malicious traffic has grown tenfold, and attackers are now trying to deliver payloads.
Patchstack says it saw the first malicious requests at 17:44 UTC on September 22. They came from a small group of IP addresses and targeted several sites under the company's protection.
Researchers at Graz University of Technology in Austria have shown that the file-change notification features in Linux, Android, Windows and macOS can be used to spy on other users of the same system. The information exposed ranges from the rhythm of someone's typing to the websites they visit.
All four operating systems let applications ask to be told when files are created, modified or deleted. Text editors, file managers, sync clients and antivirus tools rely on this. It needs no elevated privileges, only read access to the watched location.
The attacks never reveal what is inside a file. The researchers found that file names and the timing of events are enough to piece together what users, applications and the system are doing. Most scenarios assume an attacker who can already run code on the machine under a separate account. On Android, that attacker could be an app that asks for no permissions at all.
A newly discovered botnet called Carbonato is breaking into poorly secured Docker hosts and installing the Hermes Agent AI framework, which then carries out the operators' orders on compromised machines, according to ThreatDown.
The enterprise security company found the malware in an unauthenticated Docker registry that held nearly 60 repositories and 4.3 GB of image data. The operational evidence recovered from it covers the period from October 2024 to August 2026. The archive also held details on a separate campaign that pushed counterfeit cryptocurrency wallet apps, a lure that has recently shown up in Mac-focused stealer campaigns as well.
Two US senators from opposite parties want the telecommunications industry to follow a common set of cybersecurity best practices. Adoption would be voluntary, and there would be an optional certification for companies that can show they follow them.
Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday. They pointed to the Salt Typhoon campaign, in which Chinese hackers broke into nearly all of the major US telecom providers over several years.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient.”
A newly discovered Android malware-as-a-service (MaaS) platform called RemControl is going after banking customers in Europe, Canada and the Middle East. According to Group-IB, the malware spreads through malvertising campaigns that impersonate TVTap, an IPTV streaming app.
Researchers say the infrastructure behind RemControl has been running since at least May. The first samples appeared in July and already carried more than 30 phishing overlays built to capture banking credentials. Targeted countries include Italy, France, Spain, Poland and Portugal, as well as Canada and several Middle Eastern states.
Fake Google Play pages and ad-driven traffic
Victims land on fake Google Play pages that pose as the TVTap download. At least one Italian campaign used geofencing and checked mobile User-Agent strings, so only visitors who matched the intended profile would see the malicious content.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.