Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software

Cybersecurity researchers have uncovered a global cybercrime operation, dubbed "StopAndProtect," that leverages nearly 2,000 compromised WordPress websites to facilitate its malicious activities. The operation reportedly uses these hacked sites as a distributed infrastructure to spread various malware strains, maintain control over infected systems, and exfiltrate sensitive data, including documents, screenshots, and activity logs.
The core mechanism of the StopAndProtect operation involves the initial compromise of a large number of WordPress sites. Once compromised, these websites are then repurposed by the attackers to host and distribute their malicious toolkit. This strategy allows the threat actors to diversify their distribution channels, making it more challenging for defenders to block all sources of the malware. The use of legitimate, albeit compromised, websites can also help the malware evade detection by appearing to originate from trusted domains.
The researchers noted that StopAndProtect does not rely on a singular malware payload but rather employs a comprehensive suite of criminal software. This toolkit approach suggests a sophisticated operation capable of adapting its attacks and achieving multiple objectives. Such toolkits typically include various components for initial access, privilege escalation, persistence, data exfiltration, and command and control (C2) communications. The specific types of malware within the toolkit were not detailed, but they are designed to commandeer infected hosts and steal data.
The compromised WordPress sites serve multiple roles within the operation. Beyond malware distribution, they are also used as command-and-control servers, enabling the attackers to issue commands to infected machines and receive data back. Furthermore, these sites are utilized as storage repositories for exfiltrated information. This includes stolen documents, screenshots of compromised systems, and activity logs that track the status and progress of the malicious activities. Storing exfiltrated data on a network of compromised sites can make it harder for law enforcement and security teams to trace the ultimate destination of the stolen information.
The global scale of the operation, involving nearly 2,000 hacked WordPress sites, indicates a significant and widespread threat. WordPress, being the most popular content management system globally, is a frequent target for attackers due to its extensive user base and the potential for vulnerabilities in its core software, themes, or plugins. Regular patching, strong authentication, and robust security configurations are critical mitigations for website administrators to prevent their sites from being co-opted into such malicious infrastructures.
For organizations and individuals, the primary concern is the potential for malware infection and subsequent data theft. Typical mitigation strategies against such threats include maintaining up-to-date antivirus and anti-malware software, employing network intrusion detection and prevention systems, regularly backing up critical data, and educating users about phishing and social engineering tactics that often lead to initial compromises. Monitoring network traffic for unusual patterns and connections to known malicious indicators is also crucial.
This operation underscores the persistent challenge posed by cybercriminals who exploit widely used platforms for their illicit activities. The distributed nature of StopAndProtect, leveraging a vast network of compromised legitimate websites, exemplifies a common tactic to enhance resilience and evade detection. It highlights the need for continuous vigilance and proactive security measures across the digital ecosystem, from individual website administrators to enterprise security teams, to counter evolving cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed