WordPress Core Flaw Draws Rapid RCE Attempts
Threat actors wasted no time turning a patch into an exploit manual, probing WordPress sites less than five hours after the fix for CVE-2026-87902 dropped. Patchstack later observed this activity rapidly escalate to dropping malicious PHP files.
The critical Core flaw affects versions 4.7.0 through 7.1.1 and permits unauthenticated remote code execution if your setup obliges: The active theme needs a top-level directory starting with page-, alongside a readable local PHP file. The active pearcmd.php exploit route also requires specific PHP settings.
Update to WordPress 7.1.2 or your branch’s patched release—like, last week. Verify the fix everywhere, including those forgotten staging and campaign sites, and scour logs since Sept. 22 for traversal requests or surprise PHP files. Patching shuts the door; log reviews confirm if anyone sneaked in first.
Your forgotten microsite would also like a patch.
One Hacker’s AI Agents Steal 600K Card Records
A lone attacker deployed AI agents to run rampant across the internet this month, successfully infiltrating 27 organizations in just five days, according to Gambit Security. The automated looting spree hauled away upwards of 600,000 credit card records from a pair of victims and left digital skimmers lurking on over 100 other sites.
Cybercrime has rarely been this absurdly cheap. By letting three open-source AI frameworks do the heavy lifting, the hacker spent a measly $25.46 in computing costs per completed scan.
The bots were ruthless but sloppy. In one ridiculous blunder, a post-heist cleanup script went rogue and nuked 180 of a victim’s database tables—including their backups. Whoops.
Retailers need to wake up and lock down checkout scripts, tokenize stored payment data, and pray their recovery plans actually work. Meanwhile, consumers should keep an eagle eye on their bank statements for surprise shopping sprees.
The bots work quickly. Your fraud alerts should, too.
WordPress RCE Draws Attacks Within Hours
Threat actors began probing a WordPress Core vulnerability less than five hours after a patch became available.
CVE-2026-87902 can enable unauthenticated remote code execution under specific conditions.
It’s easy to deprioritize this vulnerability because exploitation depends on specific configurations. However, those conditions can change as themes, plugins, and server packages are updated.
Inventory exposed WordPress sites, patch affected versions, and review logs for suspicious traversal requests or unexpected PHP files that could indicate exploitation.
Google Fixes 108 Chrome Flaws
Google released Chrome 154 with fixes for 108 security vulnerabilities, including 11 critical flaws affecting several browser components.
Some of them involved memory-safety issues that could potentially enable code execution through malicious web content.
What stands out to me is that several of the flaws affect components used during ordinary browsing. This means a malicious webpage could create risk without an employee downloading a file or clicking anything suspicious.
Use browser management policies to enforce Chrome updates and identify endpoints that remain on vulnerable versions.
Microsoft 365 Attack Breaches 12,000 Inboxes
More than 12,000 inboxes across 10,000 organizations were compromised after EvilTokens abused Microsoft’s device-code authentication flow.
Victims could complete MFA on Microsoft’s real login page while unknowingly authorizing attacker access to their email and business conversations.
Access to real conversations lets attackers step into existing business relationships, making fraudulent requests more difficult to spot.
Restrict device-code authentication where it isn’t needed and monitor for new device registrations or unusual sign-ins following authentication.
Apache Tomcat Vulnerability Forces Another Patch
Apache disclosed a new Tomcat vulnerability after finding that an April patch for a client-certificate authentication flaw was incomplete.
CVE-2026-86248 can allow authentication to succeed despite certain OCSP failures, potentially exposing services protected by mTLS.
What concerns me most is the fail-open behavior. A certificate check designed to stop unauthorized access can instead allow authentication when validation fails.
Patch affected Tomcat systems and test that revoked certificates and OCSP validation failures are rejected rather than allowed through.
TeamFiltration Exploits Stale Microsoft 365 Accounts
Proofpoint found that TeamFiltration targeted 5,714 Microsoft 365 accounts across 28 tenants.
The attackers exploited forgotten accounts with weak credentials and no MFA rather than targeting active employee accounts.
I spoke with Proofpoint threat researchers at their recent conference, and they highlighted how AI is helping attackers expand beyond their traditional geographic targets.
Audit dormant service accounts, enforce MFA where possible, and disable identities without a verified business need.