
WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug
WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2. Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails. Arctic Wolf's report that the Killin ran...
Transcript
Automatically generated from the audio. May contain errors.
Two chained WordPress bugs have kicked off a cyber-feeding frenzy. An autonomous AI agent breaks into hugging face, while the company's own AI gets locked out trying to fight back. The killin' ransomware gang targets a Palo Alto VPN bug.
And another major healthcare supply chain breach. This is Cybersecurity Today, and I'm your host, David Shipley. Let's get started. A pair of WordPress flaws now chained together under the name WP2Shell has gone from proof of concept to internet-wide feeding frenzy.
Security firm Watchtower says its honeypots have logged tens of thousands of exploitation attempts since a working exploit hit GitHub. Researchers have already counted more than 100 backdoor administrator accounts created on compromised sites. Searchlight Cyber, the firm that found the flaws, says the attack has no preconditions and can be pulled off by an anonymous user.
Searchlight Cyber didn't find WP2 Shell by hand. They found it using OpenAI's GPT 5.6 SOL model, which reportedly worked out the full exploit chain in a little over 10 hours. Here's the chain.
WP2 Shell stitches two bugs together. CVE-2026-6330, a root confusion flaw in the REST API batch endpoint, and CVE-2026-6137, a SQL injection sitting in WordPress core. On their own, each is a mild headache. Chained, they hand an anonymous attacker remote code execution on a stock WordPress install
with no plugins, no login, and no special configuration. That's a full-blown migraine. WordPress shipped patches on Friday with versions 6.9.5 and 7.0.2, and given the severity, the project took the rare step of forcing auto-updates across affected sites.
But being patched doesn't undo a compromise. Google-owned Wiz found that by Tuesday, 60% of organizations running WordPress had at least one vulnerable instance, and a quarter were exposing one straight on the open internet.
Attackers moved quickly, uploading web shells, enumerating admin accounts, and in at least one case, trying to plant a Go-based remote access Trojan called Overlord. One of the payloads is a 150-kilobyte web shell dressed up as a legitimate security plugin called CMS Map, packing file management, database access, port scanning, and a stack of privilege
escalation models. Defenders should comb their installs for new administrator accounts, rogue plugins, and stray files, regardless of whether they've already been patched. Hugging Face, the open-source AI hub that hosts more than 45,000 models for over 50,000 organizations, says it got breached by an attacker who wasn't human. In its incident disclosure,
the company said the intrusion into its production infrastructure was driven, end to end, by an autonomous AI agent system, and that it detected and dissected the thing, largely using its own AI. Here's how it all played out. The agent started where AI platforms are most exposed, the data processing pipeline. A malicious dataset abused two code execution paths,
a remote code dataset loader and a template injection in the dataset config to run code on a processing worker. From that foothold, the attacker escalated to node-level access, harvested cloud and cluster credentials, and moved laterally across several internal clusters over a single weekend. Hugging Face says the campaign ran as a swarm of short-lived
sandboxes, each firing many thousands of individual actions with command and control that kept migrating itself across public services. In the company's own words, this matches the agentic attacker scenario the AI industry has been forecasting. The attacker made off with a limited set of internal data sets and several service credentials.
Hugging Face found no evidence of tampering with public models, data sets, or spaces, and says its software supply chain came back clean, though it's still checking whether partner or customer data was touched. Since the attack, Hugging Face has closed the vulnerable code paths,
evicted the attacker, rebuilt the compromised nodes, rotated every affected credential, and brought in law enforcement along with outside forensics. Hugging Face still doesn't know what model powered the attacker agent. It operated with no guardrail restrictions.
Hugging Face's own responders, however, were hit with the opposite problem. When they reached for hosted models to run forensics, the guardrails on those models blocked the work, and the team had to fall back to a model they could run on their own infrastructure.
The Killen ransomware crew has found its way into a Palo Alto flaw that's been sitting exposed since the spring. Arctic Wolf reported on Monday that it worked multiple distinct intrusions in June, all starting the same way. Exploitation of CVE-2026-0257, an authentication bypass in Palo Alto's PanOS Global Protect, and all ending in domain-wide Killen encryption.
The bug itself is a nasty piece of work. It lets an unauthenticated attacker forge Global Protect authentication override cookies and stand up a legitimate looking VPN session, strolling straight past perimeter authentication and into the network. Palo Alto disclosed the vulnerability back on May 13th and initially rated it as a modest 4.7. Then Rapid7 published
a working proof of concept in late May, and Palo Alto revised the score to 7.8. Exploitation had been running in the wild since May 17th. What Arctic Wolf is describing now is the ransomware phase. The trade crap varied from one intrusion to the next. Some were smash and grab, encryption only jobs. Others went the full double extortion route with data theft layered on top, which points
to several Killen affiliates working the same exploit under the ransomware as a service model. Once inside a network, they moved fast, staging payloads in the perf logs directory, spreading laterally with psexec, dumping credentials, and clearing event logs on the way through. Arctic Wolf assesses with moderate confidence that these Killen intrusions are still
ongoing. And they have lots of room to work. Shadow Server counts more than 167,000 global
This is the opening of the episode. Open the player for the full interactive transcript with clickable words, translation and flashcards.
Open full transcriptAudio belongs to its publisher and is played from their feed. Rights holders can request removal — copyright & takedown policy











