WordPress Feeding Frenzy, Another Healthcare Supply Chain Breach, Qillin Targets Palo Alto Bug

July 22
11 mins

View Transcript

Episode Description

WP2Shell WordPress RCE feeding frenzy, AI agent breaches Hugging Face, Killin hits Palo Alto VPN flaw   This episode covers five major incidents: a chained WordPress exploit dubbed WP2Shell (CVE-2026-6330 and CVE-2026-6137) enabling anonymous remote code execution on stock installs, now seeing tens of thousands of Internet-wide attempts, backdoor admin accounts, and web shell payloads despite forced auto-updates to 6.9.5 and 7.0.2.   Hugging Face's disclosure that an autonomous AI agent breached its production infrastructure via a malicious dataset, stole limited internal datasets and credentials, and forced responders to work around restrictive model guardrails.   Arctic Wolf's report that the Killin ransomware gang is exploiting Palo Alto PAN-OS GlobalProtect auth bypass CVE-2026-0257 for domain-wide encryption; and healthcare supply-chain fallout including Craneware file exfiltration.   EY client tax-data exposure via a third-party platform.   00:00 Top Stories Teaser 00:28 WP2Shell WordPress Frenzy 02:58 AI Agent Hacks Hugging Face 05:16 Killin Hits Palo Alto VPNs 07:33 Craneware Healthcare Breach 09:15 EY Third Party Data Leak 10:47 Wrap Up and Sign Off
See all episodes