A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]

BdThemes, a developer of premium WordPress web-design tools, has experienced a supply-chain compromise that led to the creation of unauthorized administrator accounts on customer websites. The incident, which began as early as June 23, involved a threat actor modifying a remote JSON feed to inject malicious code into WordPress admin dashboards.
The attack specifically targeted the Biggop Library, utilized by the Biggopti component within BdThemes plugins. This component is responsible for fetching promotional banners from the vendor's API server and displaying them in the WordPress admin dashboard. Researchers at the security firm Defiant identified a cross-site scripting (XSS) vulnerability in the JSON response parsing code, introduced in March 2026. This flaw, present in various versions of the Biggop Library, allowed an attacker who compromised the Sigmative API server to inject arbitrary web scripts due to insufficient output escaping in the `display_id` parameter.
The threat actor gained write access to BdThemes' storage bucket, enabling them to poison a static remote JSON data stream. When a logged-in administrator accessed a WordPress admin page, the malicious JavaScript executed within their authenticated session. This script then created rogue administrator accounts on the affected sites. To maintain persistence, an additional payload, `w2.js`, installed a fake plugin and established a webshell named `emer-run.php`. The injected code also manipulated WordPress database queries to conceal these rogue accounts from the user list, making detection more challenging.
Defiant's Wordfence web application firewall began detecting these attacks on August 7. The firm noted that the attack is entirely API-driven, requiring no user interaction, file modification, or plugin updates, making it particularly stealthy.
BdThemes' product portfolio includes popular plugins such as Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit. The free Element Pack plugin alone has over 100,000 active installations on WordPress.org, and the developer advertises a total of over 350,000 active installs across its offerings.
Following the discovery of the attacks, all affected BdThemes products were removed from the WordPress.org directory on August 8, pending a comprehensive review by the WordPress Plugins team. As of August 10, the two poisoned API endpoints were reportedly returning clean JSON data.
Defiant researchers have indicated that the command-and-control (C2) infrastructure used in these attacks appears to be linked to the same threat actor responsible for recent supply-chain compromises affecting the Advanced Responsive Video Embedder and OptinMonster plugins.
As of the latest reports, BdThemes has not released an official statement regarding the incident on its website. The XSS vulnerability in the Biggop Library remains unpatched, according to Defiant's report, which assigned it a medium severity score.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed