{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Wordfence Security News","title":"Burst Statistics Bypass Threatens 200,000 WordPress Sites | Microsoft Exchange Zero-Day Under Active Exploitation | Critical Cisco SD-WAN Controller Flaw Exploited | Shai-Hulud Worm Source Code Open-Sourced | Wordfence Security News | Week of May 18, 2026","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/3a70d52d\"></iframe>","width":"100%","height":180,"duration":700,"description":"This week in Wordfence Security News (Week of May 18, 2026):Burst Statistics plugin auth bypass lets unauthenticated attackers impersonate admins; Wordfence blocked 88,000+ requests across 376 sites.Microsoft Exchange OWA zero-day XSS flaw under active exploitation with no permanent patch; CISA deadline set for May 29th.Cisco Catalyst SD-WAN auth bypass exploited by UAT-8616; CISA gave federal agencies three days to patch under Emergency Directive 26-03.ChromaDB pre-auth RCE loads attacker-controlled AI models before the auth check runs; 73% of exposed instances run a vulnerable version.Shai-Hulud worm source code released on GitHub by TeamPCP; copycat packages appeared on NPM within days of publication.node-ipc npm package with 800,000 weekly downloads was compromised via an attacker re-registering a maintainer's expired email domain.Timestamps:\n\n0:00 Introduction\n0:37 Burst Statistics Auth Bypass Threatens 200K WordPress Sites\n2:52 Microsoft Exchange OWA Zero-Day Under Active Exploitation\n5:24 Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack\n7:11 ChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover\n9:24 Shai-Hulud Worm Source Code Released on GitHub\n11:02 node-ipc npm Package Compromised via Expired Maintainer Domain\nStory Links:Burst Statistics Auth Bypass Threatens 200K WordPress Sites: https://www.wordfence.com/blog/2026/05/200000-wordpress-sites-at-risk-from-critical-authentication-bypass-vulnerability-in-burst-statistics-plugin/Microsoft Exchange OWA Zero-Day Under Active Exploitation: https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498Critical Cisco Catalyst SD-WAN Controller Auth Bypass Under Attack: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SWChromaDB Pre-Auth RCE Allows AI Vector Database Server Takeover: https://www.hiddenlayer.com/research/chromatoast-served-pre-authShai-Hulud Worm Source...","thumbnail_url":"https://img.transistorcdn.com/tNZ1BCLBa7hdisGHRggcQKe1fS0BRjNwLU5euMPMXfE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}