Wordfence Security News

This week in Wordfence Security News (Week of Apr 6, 2026):
  • An arbitrary file upload vulnerability in Ninja Forms File Upload puts 50,000+ WordPress sites at risk
  • A Fortinet zero-day actively exploited in the wild
  • A CERT-EU report reveals a European Commission cloud breach tied to a Trivy supply chain attack — with Cisco source code stolen in the fallout
  • Anthropic announces Project Glasswing
  • Germany doxes "UNKN," the head of the REvil and GandCrab ransomware gangs
Story Links:
Stay informed and secure: get the latest WordPress security news on the Wordfence blog or subscribe to the WordPress Security Newsletter.

What is Wordfence Security News?

Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.

Alex Thomas:

This week on Wordfence Security News, 50,000 WordPress sites are targeted by a critical file upload vulnerability, a Fortinet zero day catches enterprise security teams off guard over the holiday weekend, and a new AI initiative could reshape how the finds and fixes vulnerabilities. This is Wordfence Security News for the week of 04/06/2026. I'm Alex Thomas. Our top WordPress story this week is active exploitation of a critical unauthenticated vulnerability in the Ninja Forms file upload plugin, which has an estimated 50,000 active installations. The flaw is in how the plugin handles destination file names during uploads.

Alex Thomas:

It validates the type of file you're uploading, so it'll check that you're sending a JPEG, for example, but the destination file name where that file actually gets written on the server comes from a separate parameter that had no validation at all in vulnerable versions. So an attacker could send what looks like a harmless image while the server writes it as a PHP backdoor or an HT access file to a location of the attacker's choosing. The Wordfence firewall has now blocked over 5,100 exploit attempts, targeting this vulnerability across nearly 2,500 sites. What caught our researchers' attention in the data is the pre disclosure activity. Starting in early March, three IP addresses were running file read probes against this flaw, which are classic validation techniques attackers use to confirm a vulnerability works before they commit real payloads.

Alex Thomas:

That was a full month before we published the disclosure on April 6. Once the disclosure went out, exploitation scaled up immediately. Over 3,700 block requests on day one alone. And since then, 111 new source IPs have appeared. On disclosure day, one IP was responsible for over 72% of all traffic.

Alex Thomas:

Two days later, that share has dropped to 55%, which tells us more attacker groups are adopting this vulnerability into their exploit tooling. We're also seeing new payload types. PHP web shell uploads showed up for the first time on April 7 and were continuing through April 8. All Wordfence Premium, Care, and Response users have been protected since January 8. Free users received the same rule on February 7.

Alex Thomas:

If you're running Ninja Forms file upload, update to 3.3.27 now. The patch has been available since March 19. The biggest enterprise story this week is an actively exploited zero day in Fortinet's FortiClient Enterprise Management Server or EMS, the platform organizations use to centrally manage endpoint security across their device fleet. Fortinet says the vulnerability allows an unauthenticated attacker to send crafted requests to the EMS API and execute unauthorized code or commands on the server. It affects versions 7.4.5 and 7.4.6.

Alex Thomas:

Watchtower says its sensors saw exploitation activity on March 31, four days before Fortinet published its advisory. Fortinet has since released hotfixes and says it has observed the flaw being exploited in the wild. Researchers at Diffused who reported the flaw to Fortinet described it as a pre authentication API access bypass. They described the flaw as ridiculously easy to exploit. Their words, which is why they've deliberately withheld a public proof of concept.

Alex Thomas:

They have, however, shared indicators of compromise, including two attacker IP addresses and a detection indicator. Their post on X says to look for traffic from unknown IPs with the XSSL client verify header set to success. We'll link to those details in the description. This is also the second critical unauthenticated Fortinet EMS vulnerability in a matter of weeks. An earlier flaw was also actively exploited, underscoring how exposed internet facing EMS deployments have become.

Alex Thomas:

CISA added this latest vulnerability to its Known Exploited Vulnerabilities Catalog on April 6 and gave federal agencies until April 9 to patch. If you're running FortiClient EMS, this belongs at the very top of the list. A quick update on the Trivy supply chain story from last week. CERT EU published its investigation on April 2 and confirmed with high confidence that the European Commission breach was also a direct result of the Trivy compromise. The commission was unknowingly running a compromised version of Trivy, which gave attackers an AWS API key and access to cloud infrastructure hosting europa.eu.

Alex Thomas:

CertEU says data from up to 71 clients was affected. Both breaches now trace back to the threat group Team PCP. Shifting to the broader industry, Anthropic announced a cybersecurity initiative this week called Project Glasswing built around an unreleased AI model called Claude Mythos Preview Anthropic says the model has identified thousands of previously unknown vulnerabilities across every major operating system and every major browser, including some that had gone undetected for decades. The company's Red Team published technical details on a subset of them, including a seventeen year old remote code execution flaw in FreeBSD and a browser exploit chain that linked four separate vulnerabilities together to escape both the renderer and OS sandboxes. The company says it's deliberately withholding the model from general availability because of its offensive capabilities and is instead routing access through a coalition that includes AWS, Apple, Google, Microsoft, and Palo Alto Networks, among others.

Alex Thomas:

Whether the capability claims hold up under independent scrutiny remains to be seen, but if these models can find and fix vulnerabilities at scale before attackers reach them, that changes the math on defensive security. And finally this week, Germany's Federal Criminal Police, the BKA, has put a name and a face to one of the most notorious figures in ransomware history. A hacker known for years only as Unknown, who was linked to the Gand Crab and later the Reval ransomware operations, has been identified as 31 year old Russian national Daniil Shukin. The BKA says he and a second individual responsible for at least 130 attacks against German organizations, causing more than €35,000,000 in damage. Shukin is believed to be in Russia and no arrest has been announced.

Alex Thomas:

Links to all the stories we covered today are in the description. Thanks for and we'll see you next week on Wordfence Security News.