Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.
This week on Wordfence Security News, more than 200,000 WordPress sites may be at risk from a newly disclosed plugin vulnerability, a major supply chain attack targets the widely used Axios package, and security firms are warning of active exploitation of critical vulnerabilities in internet facing infrastructure. This is Wordfence Security News for the week of 03/30/2026. I'm Alex Thomas. Our top WordPress story this week is a new disclosure from the Wordfence research team. This vulnerability is an unauthenticated arbitrary file move vulnerability in MWWP form, a plugin with more than 200,000 active installations.
Alex Thomas:In vulnerable versions through 5.1.0, attackers can move arbitrary files on the server, including wp config. Php, which can lead to full site takeover and remote code execution. No authentication is required, though the vulnerability does depend on a specific configuration setting being enabled. The patched version five point one point one is available now. If you're running MWWP form, update immediately.
Alex Thomas:All Wordfence users are protected through its built in local file inclusion protection. Last week, we reported on same day exploitation of a critical remote code execution in the KaldiForms plugin. At the time, our data showed just over 400 attempts from about 60 IPs. One week later, that number has jumped to over 10,600 attempts. Activity after March 25 was roughly 64 times higher than the week before.
Alex Thomas:The majority of new traffic appears to be recon with attackers probing sites to confirm they're vulnerable before attempting the admin takeover payload. If you haven't updated Kali forums to 2.4.10 or later, you are actively being targeted. The biggest enterprise story this week is a supply chain attack targeting one of the most widely used JavaScript libraries in the ecosystem. Axios is a JavaScript library developers use to move data between apps and services over the web. It's downloaded roughly 100,000,000 times a week, and according to the cloud security firm Wizz, it's present in about 80% of cloud and code environments.
Alex Thomas:An attacker compromised an Axios maintainer account and used it to push malicious updates to the real Axios package, the genuine library trusted by developers around the world. Those malicious versions quietly installed a backdoor on any machine that downloaded them across macOS, Windows, and Linux. They were live for about two to three hours before they were discovered and removed. Google's threat intelligence group has linked the attack to a North Korean threat actor tracked as UNC ten sixty nine. Despite being live for only two to three hours, that short window was still enough to matter.
Alex Thomas:Wizz says it found the compromised versions in roughly 3% of the environments it scanned. At Axios' scale, that could translate into a significant number of exposed systems. If your teams use Axios, it's worth checking whether any systems installed versions one point fourteen point one or zero point thirty point four during that window. If they did, those systems should be treated as compromised. Also this week, the Cybersecurity and Infrastructure Security Agency added a critical Citrix Netscaler vulnerability to its known exploited vulnerabilities catalog following evidence of active exploitation.
Alex Thomas:Citrix Netscaler is widely used as an edge access and application delivery platform, often sitting in front of enterprise applications and handling traffic, authentication, and remote access. The flaw affects Netscaler ADC and gateway appliances configured as SAML identity providers. Researchers at Watchtower confirmed that attackers can use it to read sensitive data from device memory, including active administrator session IDs, which could allow session hijacking and full compromise of an unpatched device. Citrix released patches on March 23. By March 27, researchers were already seeing reconnaissance against vulnerable endpoints, and by March 30, active exploitation had been reported in the wild.
Alex Thomas:Multiple security firms have compared the bug to Citrixbleed and Citrixbleed two, which are earlier Citrix memory disclosure flaws that were widely exploited in 2023 and 2025. Reporting, citing ShadowServer, says there are roughly 30,000 Netscaler ADC appliances and a little over 2,000 gateway instances exposed to the Internet, though it's still unclear how many are running the vulnerable configuration. CISA gave federal agencies until Thursday, April 2, to patch. If you're running Netscaler as a SAML identity provider, this belongs at the top of your vulnerability prioritization list. The European Commission confirmed this week that attackers breached cloud infrastructure hosting its europa.eu web platform and stole data.
Alex Thomas:This is the second breach the Commission has disclosed this year. Back in February, a separate intrusion may have exposed staff personal data. This latest incident was discovered on March 24, and the commission says its internal systems were not affected, but it is still investigating the full extent of this breach. The extortion group, Shiny Hunters, has claimed responsibility, saying it stole more than three fifty gigabytes of data. They've already published about 90 gigabytes of files on their leak site, though the full scope of their claims hasn't been verified.
Alex Thomas:Bloomberg reports the breach hit the Commission's Amazon Web Services account. Amazon says it did not suffer a security event on its side, which suggests the attackers got in through a compromised account rather than a vulnerability in AWS. The other major story this week ties directly back to supply chain risk. According to reporting from Bleeping Computer, attackers used credentials stolen in the recent Trivy supply chain compromise to breach Cisco's internal development environment and steal source code. Trivy is a widely used open source vulnerability scanner, and earlier this month, a threat group called Team PCP poisoned official Trivy release channels and GitHub actions to distribute credential stealing malware.
Alex Thomas:Cisco's build environment ran the compromised tooling which allowed attackers to harvest credentials and move deeper into the company's development systems. More than 300 GitHub repositories were cloned, including code tied to Cisco AI products and repositories belonging to corporate customers. Multiple AWS keys were also stolen. Cisco's response teams have reportedly contained the initial breach, but the company expects continued fallout. What both of these incidents show and what the Axios attack earlier in this episode also demonstrates is that attackers are increasingly going after the tools developers use to build and secure software.
Alex Thomas:If you can compromise something developers trust, you could inherit access to the organizations that rely on it. Links to all the stories we cover today are in the description. Thanks for watching or listening, and we'll see you next week on Wordfence Security News.