2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin episode artwork

EPISODE · May 17, 2026 · 11 MIN

2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin

from Cyber Threat Brief

Show Notes - 2026-05-17 Stories Covered: - Today: - Funnel Builder Plugin Skimming Campaign (Active Exploitation) (https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html) - NGINX Heap Overflow (CVE-2026-42945) (https://www.securityweek.com/poc-code-published-for-critical-nginx-vulnerability/) - Azure Kubernetes Privilege Escalation (Silent Fix) (https://www.bleepingcomputer.com/news/security/microsoft-rejects-critical-azure-vulnerability-report-no-cve-issued/) - BlackFile Vishing Extortion Campaign (UNC6671) (https://databreaches.net/2026/05/16/welcome-to-blackfile-inside-a-vishing-extortion-operation/) - Grafana GitHub Token Compromise and Extortion (https://thehackernews.com/2026/05/grafana-github-token-breach-led-to.html) - Instructure-ShinyHunters Payment Debate (https://databreaches.net/2026/05/16/another-detail-emerges-about-instructures-agreement-with-shinyhunters-debate-continues-about-whether-to-pay/) - Illuminate Education Data Breach Lawsuit (https://databreaches.net/2026/05/16/illuminate-wins-another-round-in-court-but-it-may-not-all-be-over/) - Russian Kazuar Backdoor Evolves to P2P Botnet (https://www.bleepingcomputer.com/news/security/russian-hackers-turn-kazuar-backdoor-into-modular-p2p-botnet/) - Medicare Fraud Using Stolen Patient Records (https://databreaches.net/2026/05/16/michigan-nurse-convicted-in-1-6m-medicare-fraud-scheme-using-stolen-patient-records/) - CVE-2026-46483 (Vim Command Injection) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46483) - CVE-2026-44283 (etcd RBAC Bypass) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44283) - CVE-2026-8368 (Perl LWP::UserAgent Header Leak) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8368) - CVE-2026-8328 (Perl FTP PASV SSRF) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-8328) CVEs Referenced: CVE-2026-42945, CVE-2026-44283, CVE-2026-46483, CVE-2026-8328, CVE-2026-8368 Indicators of Compromise: Domains: protect-wss[.]com IPs: 3.15.0.3 Full brief: https://carolinacleartech.com/brief/2026-05-17/

Episode metadata supplied by the publisher feed · Published May 17, 2026

Embed this episode

Show Notes - 2026-05-17 Stories Covered: - Today: - Funnel Builder Plugin Skimming Campaign (Active Exploitation) (https://thehackernews.com/2026/05/funnel-builder-flaw-under-active.html) - NGINX Heap Overflow (CVE-2026-42945) (https://www.securityweek.com/poc-code-published-for-critical-nginx-vuln

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-17: WordPress e-commerce stores face active skimmer attacks via unpatched Funnel Builder plugin

0:00 11:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 11 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 17, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!