Attackers pummel critical WordPress vuln to create all sorts of mischief

https://image.theregister.com/5275290.jpg?imageId=5275290&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Plus dozens of PoCs in the public domain

If you use WordPress, patch now. Just hours after fixes came out, attackers have begun exploiting two bugs that, when chained together, allow pre-authentication remote code execution (RCE). And security researchers tell us there’s a very good chance the miscreants had an AI assist.

“Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens,” Jake Knott, watchTowr principal security researcher, told The Register. “WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.”

WordPress released patches for both CVEs late Friday, but by Saturday it was game over.

“By the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more

https://www.techdirt.com/wp-content/uploads/2022/02/failures.jpg

SpaceX's earnings show X's Q2 ad revenue at $367M, down from $1.08B at Twitter in Q2 2022; Musk once said he would take its annual ad revenue to $12B in 2027

More: 404 Media, TechCrunch, The Information, The Verge, New York Magazine, Ars Technica, The Register, Washington Post, Globe and Mail, SiliconANGLE, NBC News, CBS News, Forbes, RuntimeWire, The Wrap, Bloomberg, Constellation Research, Futurism, Breitbart, CNN, ZeroHedge News, Variety, UPI, WeRSM, Fortune, Gizmodo, Caliber.az, The Post Millennial, Tech Times, Bitcoin