{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Wordfence Security News","title":"Google Identifies First AI-Developed Zero-Day | Gravity SMTP Mass Exploitation Leaks API Keys | Palo Alto Firewall Flaw Exploited by State Actors | TanStack Release Pipeline Hijacked | Wordfence Security News | Week of May 11, 2026","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/55ee78c9\"></iframe>","width":"100%","height":180,"duration":608,"description":"This week in Wordfence Security News (Week of May 11, 2026):Active mass exploitation of an information disclosure vulnerability in Gravity SMTP exposes API keys and mail service credentials, with the Wordfence firewall blocking nearly 788,000 exploit attempts across more than 77,000 unique WordPress sitesA critical authentication bypass in cPanel and WHM is now under active exploitation, allowing unauthenticated attackers to gain administrative access and potentially compromising every WordPress site on a shared hostSuspected state-sponsored attackers exploit a Palo Alto PAN-OS zero-day buffer overflow in the User ID Authentication Portal, achieving root code execution on PA series and VM series firewalls and pivoting via high-availability failoverThe Shai-Hulud supply chain worm returns as attackers hijack TanStack's GitHub Actions release pipeline, publishing over 170 malicious packages across NPM and PyPI with valid signatures and provenance attestationsGoogle's Threat Intelligence group identifies the first zero-day exploit believed to have been developed with AI assistance, targeting a two-factor authentication bypass in an unnamed open source web administration toolA Linux kernel privilege escalation vulnerability called Dirty Frag becomes public after its coordinated disclosure embargo collapses, with Microsoft Defender reporting limited in-the-wild exploitation for root escalation after SSH accessTimestamps:\n0:00 Introduction\n0:33 Gravity SMTP Information Disclosure Exploitation\n3:19 cPanel and WHM Authentication Bypass\n4:22 Palo Alto PAN-OS Zero-Day\n5:56 Shai-Hulud Supply Chain Worm Hits TanStack\n7:09 Google Identifies First AI-Assisted Zero-Day\n8:24 Dirty Frag Linux Kernel Privilege Escalation\nStory Links:Gravity SMTP Exploited at Scale: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/gravitysmtp/gravity-smtp-214-unauthenticated-sensitive-information-exposure-via-rest-apiPAN-OS zero-day:...","thumbnail_url":"https://img.transistorcdn.com/tNZ1BCLBa7hdisGHRggcQKe1fS0BRjNwLU5euMPMXfE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNjZm/M2NiNzczNWQ4MDdh/OTYyMTg5MDQ5ODk3/ODI5ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}