🔐 Security Pulse · 2026-10-04 16:00 UTC
⚡ TL;DR
Emerging threat actor "Rey," linked to ShinyHunters extortion group, has been apprehended in Jordan with FBI cooperation—significant disruption in cybercrime network. Overall cyber threat level remains elevated due to multiple critical WordPress plugin vulnerabilities affecting global websites.
🔐 CYBER THREATS
🔴🔴 Rey, core member of ShinyHunters extortion group, arrested in Jordan; disruption of ongoing ransomware/extortion operations impacting global victims [1].
🟡 CVE-2026-93896 WPFront Notification Bar WordPress plugin vulnerable to reflected cross-site scripting, risking site defacement and user data theft [2].
🟡 CVE-2026-93889 Mail logging – WP Mail Catcher plugin for WordPress has stored XSS via PHPMailer failures, enabling persistent attacks [3].
🟡 CVE-2026-87115 VikAppointments Services Booking Calendar WordPress plugin allows arbitrary file deletion, risking site integrity and data loss [4].
🟡 CVE-2026-103519 WP Ultimate Review WordPress plugin vulnerable to arbitrary shortcode execution leading to remote code execution risks [5], [6].
🟡 CVE-2026-96267 WP Visitor Statistics plugin vulnerable to SQL injection, exposing backend databases to tampering or data exfiltration [7].
🟡 CVE-2026-94505 Nelio Content plugin suffers authorization bypass, potentially allowing unauthorized content manipulation [8].
🟡 CVE-2026-104313 WPC Estimated Delivery Date WooCommerce plugin is exposed to reflected XSS, enabling phishing and session hijacking attacks [9].
🟡 CVE-2026-18443 Smart Manager WooCommerce plugin vulnerable to SQL injection through access_privileges parameter, risking escalation and data leakage [10].
🟡 CVE-2026-11601 WPCafe Restaurant Menu plugin authorization bypass risks customer data and order manipulation.
🟡 CVE-2026-92084 Beaver Builder Page Builder plugin vulnerable to arbitrary shortcode execution, a vector for website compromise.
🟡 CVE-2026-92767 Twenty20 Image Before-After plugin suffers stored XSS via shortcode attributes, enabling persistent website scripting attacks.
🟡🔴 NASA AMMOS AIT-Core telemetry and command broker (ait-server) contains missing authentication in critical functions, enabling remote command execution and telemetry compromise.
🟡 Nezha monitoring software suffers deadlock and mutex unlocking flaws allowing denial of service by authenticated non-admin users,.
🟡 OpenAM versions before 16.1.3 contain multiple critical vulnerabilities: reflected XSS, unauthenticated arbitrary class instantiation, and latent XSS in SAML cookie handling risking server takeover and credential theft,,.
🛡️ NATIONAL SECURITY
🟢 FBI-Jordan joint operation led to capture of "Rey," a key figure in ShinyHunters, aiding in disruption of a major extortion and data theft network impacting international cybercrime ecosystem [1].
🟡 NASA's AIT-Core system vulnerabilities could enable adversaries to interfere with telemetry and command workflows at critical space operations facilities, posing risks to mission safety.
⚠️ RISK FLAGS
⚠️🔴 The missing authentication vulnerability in NASA's AIT-Core command broker (CVE-2026-105105) represents an immediate risk to space operation integrity and must be quickly remediated.
⚠️ Growing patch backlog for multiple WordPress ecosystem vulnerabilities including arbitrary code execution and SQL injection attacks risks mass exploitation across global infrastructure [3-14].
⚠️ OpenAM legacy versions still in active use expose government and enterprise federated identity services to remote takeover and persistent cross-site scripting attacks [18-20].
🧭 THREAT MOOD
🟡 Elevated threat level: Law enforcement successes contain key APT criminal threat actors, but prevalent high-impact software vulnerabilities alongside emerging aerospace system risks maintain significant threat environment pressure.
📎 Sources
- A Threat Actor operating under the moniker "Rey" has been appr… — @vxunderground
- CVE-2026-93896 The WPFront Notification Bar plugin for WordPre… — @CVEnew
- CVE-2026-93889 The Mail logging – WP Mail Catcher plugin for W… — @CVEnew
- CVE-2026-87115 The VikAppointments Services Booking Calendar p… — @CVEnew
- CVE-2026-103519 The The WP Ultimate Review plugin for WordPres… — @CVEnew
- CVE-2026-100157 The The WP Ultimate Review plugin for WordPres… — @CVEnew
- CVE-2026-96267 The WP Visitor Statistics (Real Time Traffic) p… — @CVEnew
- CVE-2026-94505 The Nelio Content – Editorial Calendar & So… — @CVEnew
- CVE-2026-104313 The WPC Estimated Delivery Date for WooCommerc… — @CVEnew
- CVE-2026-18443 The Smart Manager – Advanced WooCommerce Bulk E… — @CVEnew
Educational & informational only — not financial advice. Markets carry risk; do your own research.
Serial 20261004-16-v90 · 2026-10-04 16:00 UTC · pulse.uzylab.com