Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.
More than 30,000 WordPress sites may be at risk from a newly discovered flaw in the TutorLMS Pro plugin. The bug allows threat actors to log in as another user without knowing their password, potentially giving them access to a website. This is Wordfence Security News for the week of 03/09/2026. I'm Alex Thomas. Back to our top story.
Alex Thomas:Researchers have disclosed an authentication bypass vulnerability affecting the TutorLMS Pro plugin used by online learning platforms built on WordPress. Here's how it works. When you sign in through Google, the plugin receives a token containing your email and a separate email field in the login request. Normally, those match because it's the same person. The flaw is that the plugin never verified they matched.
Alex Thomas:So an attacker could send a valid token from their own Google account, but swap the email field to a site administrator's address, and the plugin would log them in as that admin. Wordfence's WAF rule for the vulnerability has logged over 8,700 requests since mid January. After decoding every request, we confirmed over 1,400 as malicious, including 632 confirmed exploit attempts where we can see the email mismatch in the data. Let's take a look at the attack trend. Attack volume was low through January and February, then spiked sharply in the last seventy two hours.
Alex Thomas:One attacker account targeted over 400 sites. If you're running Tutor LMS Pro, update to three point nine point six now. Also this week, an unauthenticated SQL injection vulnerability was disclosed in the Ally WordPress plugin, which is installed on more than 400,000 sites. That flaw could allow threat actors to extract sensitive data like password hashes from a site's database without logging in. Upgrade to four point one point zero or later as soon as possible.
Alex Thomas:It's the second week of the month, which means Microsoft released its Patch Tuesday updates around 80 vulnerabilities across Windows and Office products, a high severity Excel vulnerability that Microsoft says could let Copilot agent mode exfiltrate data through unintended network egress via a zero click information disclosure attack. The specific flaw is tagged as improper input neutralization during web page generation, which is the same description used for cross site scripting class bugs and shows how AI assistants embedded in everyday apps can become attack channels. Microsoft also patched two critical Office remote code execution bugs that can be triggered through the preview pane alone. More than half of this month's fixes were privilege escalation vulnerabilities, and six bugs were rated by Microsoft as more likely to be exploited. We recommend prioritizing patching based on your specific environment.
Alex Thomas:The biggest enterprise story right now involves Cisco. On February 25, Cisco disclosed a maximum severity zero day vulnerability in Catalyst SD WAN. Cisco Talos has published indicators and investigative guidance and today marks a US Cybersecurity and Infrastructure Security Agency deadline for federal agencies to report the hardening steps they've taken. Cisco SD WAN controllers manage how traffic moves between offices, data centers, and cloud environments. Compromising one can give threat actors visibility into large portions of a company's network traffic.
Alex Thomas:The vulnerability has reportedly been exploited since at least 2023. The activity was first publicly tied to the campaign by Australian cybersecurity authorities as part of a Five Eyes effort. The US Cybersecurity and Infrastructure Security Agency issued an emergency directive giving federal agencies forty eight hours to patch, and Five Eyes partners released a joint advisory. What makes this attack particularly interesting is the chain of exploits involved. The threat actor tracked by Cisco as UAT8616 first uses an authentication bypass to get into the system.
Alex Thomas:Then they downgrade the controller software to an older version that contains a different vulnerability from 2022. That second flaw allows them to gain root level access to the device. Once that's done, they restore the original software version to make the system appear unchanged. Public exploit code has already started appearing online, which means threat actors beyond the original threat group now have a blueprint for the attack. On Tuesday, the Iran linked group, Handala, claimed responsibility for a destructive cyber attack against medical device maker, Stryker.
Alex Thomas:The group says it wiped more than 200,000 systems across 79 countries and stole 50 terabytes of data, though these numbers haven't been independently verified. Stryker confirmed a global disruption affecting its Microsoft environment, and employees in multiple countries reported corporate devices suddenly becoming unusable. Reports suggest the attackers may have abused enterprise device management tools to remotely reset systems rather than deploying traditional wiper malware, though the exact method hasn't been confirmed. In related news, earlier this month, Iranian drones hit two Amazon Web Services data centers in The UAE, while a nearby strike damaged infrastructure at a third site in Bahrain, disrupting cloud services across the region. IRGC linked media later claimed responsibility for the Bahrain strike.
Alex Thomas:Links to all the stories we covered today, including the Wordfence Vulnerability Report and Cisco Security Advisories, are in the description. Thanks for watching or listening, and we'll see you next week on Wordfence Security News.