EPISODE · May 17, 2026 · 11 MIN
2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin
from Cyber Threat Brief
Show Notes - 2026-05-17 Stories Covered: - Today: - Funnel Builder Plugin Skimming Campaign (Active Exploitation) (https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html) - NGINX Heap Overflow (CVE-2026-42945) (https://www.securityweek.com/poc-code-published-for-critical-nginx-vulnerability/) - Azure Kubernetes Privilege Escalation (Silent Fix) (https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/) - BlackFile Vishing Extortion Campaign (UNC6671) (https://databreaches.net/2026/05/16/welcome-to-blackfile-inside-a-vishing-extortion-operation/) - Grafana GitHub Token Compromise and Extortion (https://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html) - Instructure-ShinyHunters Payment Debate (https://databreaches.net/2026/05/16/another-detail-emerges-about-instructures-agreement-with-shinyhunters-debate-continues-about-whether-to-pay/) - Illuminate Education Data Breach Lawsuit (https://databreaches.net/2026/05/16/illuminate-wins-another-round-in-court-but-it-may-not-all-be-over/) - Russian Kazuar Backdoor Evolves to P2P Botnet (https://www.bleepingcomputer.com/news/security/russian-hackers-turn-kazuar-backdoor-into-modular-p2p-botnet/) - Medicare Fraud Using Stolen Patient Records (https://databreaches.net/2026/05/16/michigan-nurse-convicted-in-1-6m-medicare-fraud-scheme-using-stolen-patient-records/) - CVE-2026-46483 (Vim Command Injection) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46483) - CVE-2026-44283 (etcd RBAC Bypass) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44283) - CVE-2026-8368 (Perl LWP::UserAgent Header Leak) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8368) - CVE-2026-8328 (Perl FTP PASV SSRF) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8328) CVEs Referenced: CVE-2026-42945, CVE-2026-44283, CVE-2026-46483, CVE-2026-8328, CVE-2026-8368 Indicators of Compromise: Domains: protect-wss[.]com IPs: 3.15.0.3 Full brief: https://carolinacleartech.com/brief/2026-05-17/
Embed this episode
What this episode covers
Show Notes - 2026-05-17 Stories Covered: - Today: - Funnel Builder Plugin Skimming Campaign (Active Exploitation) (https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html) - NGINX Heap Overflow (CVE-2026-42945) (https://www.securityweek.com/poc-code-published-for-critical-nginx-vuln
NOW PLAYING
2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin
No transcript for this episode yet
Similar Episodes
No similar episodes found.