The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.
Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.
A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.
Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.
CISA added a critical ownCloud flaw to its exploited-vulnerabilities catalog after attackers used it to steal data from a research organization. Tracked as CVE-2023-49105 and scored 9.8, the WebDAV authentication-bypass bug lets an unauthenticated attacker who knows a victim's username read, modify, or delete that user's files when no signing key is configured, which is the platform's default. Disclosed back in November 2023, it affects ownCloud Server core versions 10.6.0 through 10.13.0 and was fixed in 10.13.1, yet unpatched instances remain exposed nearly two years later. Public exploit code exists, and CISA set a short deadline for federal agencies, underscoring that long-standing self-hosted flaws keep getting weaponized.
A critical flaw in GiveWP, a WordPress donation and fundraising plugin installed on more than 100,000 sites, lets an unauthenticated attacker run commands on the hosting server. Tracked as CVE-2026-82222, it chains three weaknesses: an unsafe PHP deserialization helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that turns that into system command execution. Although exploitation normally needs an account, an exposed registration action lets an attacker create one even when registration is disabled, making it effectively unauthenticated. It affects versions up to 4.16.7.1 and is fixed in 4.16.7.2, which blocks serialized data during donation processing.
A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.
Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.
Cosmos Labs warned that attackers are actively exploiting a flaw in its Cosmos EVM module, the component that gives Cosmos blockchains Ethereum compatibility, and urged affected chains to halt their validators. The bug lies in how the module handles state during nested transactions, letting an attacker manipulate balance and ownership tracking to move funds without authorization. Because many independent chains share the same module code, the weakness is systemic: separate chains were hit in the days before the ecosystem-wide warning, suggesting attackers generalized one exploit across the shared codebase. A patch existed from earlier in the year, but new exploitation shows the risk persists. It echoes supply-chain risk applied to blockchain infrastructure.
Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.