www.securityweek.com 11 Sept 2026, 14:19 UTC

Critical WordPress Flaw Enables Webshell Uploads, Threatening Sites

Critical WordPress Flaw Enables Webshell Uploads, Threatening Sites
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

SECURITYWEEK’S round-up this week touches a breadth of emerging techniques and enforcement actions shaping the cyber threat landscape. Notably, attackers are experimenting with invisible Unicode tag characters to evade phishing filters, a method linked to AI prompt injection that has driven up to 2.37 million messages per day in a February–June campaign.

While the technique’s reach is broad, specific operational details remain limited, underscoring the need for robust, multi-layered detection beyond surface text claims.

On the software side, WordPress users are being urged to patch CVE-2026-14894, a critical flaw in the Super Forms plugin that allows unauthenticated file uploads and potential execution of PHP webshells; the advised fix is to update to version 6.3.314. In parallel, a former AT&T staff member received a prison sentence for facilitating SIM swaps that helped criminals drain bank accounts, with several victims’ losses and typical payoffs cited for context.

The report also highlights InjectEave, a new class of electromagnetic side-channel attacks that can extract private audio or appliance states from 11 tested devices without tampering with hardware.

Evidence and responses are tempered across items: VulnCheck’s Glasswing review questions the solidity of Anthropic’s findings and severity assessments, while US authorities offer up to $10 million for information locating Amir Yaryab, a figure linked to IRGC cyber operations. Taken together, the notes emphasise practical risk management, timely patching, and careful interpretation of advanced attack demonstrations amid continuing geopolitical cyber activity.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline