Wordfence Security News is a weekly cybersecurity news podcast covering the top news stories from the world of WordPress security and the broader cybersecurity threat landscape. Hosted by cybersecurity expert and Wordfence researcher Alex Thomas.
This week on Wordfence Security News. New WordPress plugin vulnerabilities are putting websites at risk. Attackers are exploiting a critical Cisco flaw tied to ransomware, and US federal agencies are warning that hackers are now targeting commercial messaging app accounts. This is Wordfence Security News for the week of 03/23/2026. I'm Alex Thomas.
Alex Thomas:Our top story this week is same day exploitation of a critical vulnerability in the Kali forms plug in. The flaw is a high severity remote code execution vulnerability affecting all versions through 2.4.9. The CVE was published late last week on March 20, and according to Wordfence threat data, exploitation started the same day. The plugin takes user submitted form data and passes it into PHP's callUserFunc function without restricting what gets called. That means threat actors can submit a form with a PHP function name as the value and the target site executes it without requiring any authentication or authorization.
Alex Thomas:The real world impact here is full admin takeover with a single request. Wordfence WAF data shows four thirty eight attempts from 59 IPs since disclosure on March 20. About 15% of that traffic is coming through Tor, a network designed to help hide where internet traffic is coming from. If you're running Kali forums, we urge you to update to version 2.4.10 or later now. We're also tracking active mass exploitation of the S2 Member plugin.
Alex Thomas:The threat is an account takeover through the password reset flow. In vulnerable versions of the plugin, threat actors can inject a password field into the lost password form and reset any user's password, including administrators. The vulnerability was disclosed in February, and a patch has been available for over a month. Exploitation peaked on March 19 at more than 750 attempts in a single day, but it hasn't slowed down. Our data from this week shows the campaign ramping back up with more than 180 attempts on March 25.
Alex Thomas:Wordfence threat intelligence data shows 92 unpatched sites have been actively targeted and none of them have applied the available patch. Before we move on, a quick update out of Washington. Iran linked hackers, Handala, are claiming they breached the personal email account of FBI director, Kash Patel. According to Reuters, US officials say the material appears to be authentic, and an investigation is now underway. The incident highlights ongoing cyber activity targeting senior government officials.
Alex Thomas:The biggest enterprise security story this week involves Cisco again. Two weeks ago, we covered a critical zero day in Cisco's SD WAN infrastructure. This week, it's Cisco's firewall management platform. According to Amazon Threat Intelligence, the Interlock ransomware gang exploited a maximum severity flaw in Cisco Secure Firewall Management Center as a zero day starting January 26, more than a month before Cisco publicly disclosed and patched it on March 4. Amazon spotted the activity through its MadPot Honeypot Network, which is designed to attract and analyze malicious traffic.
Alex Thomas:The bug is an insecure Java deserialization flaw in the FMC web management interface that allows an unauthenticated remote attacker to execute arbitrary code as root. AWS researchers then went a step further. They impersonated a compromised system to trigger the next stage of the attack. That allowed them to recover more of Interlock's toolkit, including a memory resident web shell that avoids writing to disk and a log wiping script that runs every five minutes. The Interlock Group has previously been linked to attacks on DaVita, Kettering Health, Texas Tech University, and the city of Saint Paul, Minnesota.
Alex Thomas:The Cybersecurity and Infrastructure Security Agency added the flaw to the known exploited vulnerabilities catalog on March 19 and gave federal agencies until March 22 to patch, which means attackers were already using it in real world attacks. Cisco's Firewall Management Center is the platform that manages firewall policies, intrusion prevention, URL filtering, and malware protection across an environment. So if attackers compromise FMC, they are not just getting into the network, They may be gaining leverage over the very systems meant to defend it. If you're running Cisco FMC and you haven't patched, this should be treated as an emergency. And beyond patching, admins should verify whether the management interface is publicly exposed because Cisco says that directly affects the attack surface.
Alex Thomas:One other thing worth noting is that based on our research, public exploit code is already circulating, but not all of it appears to line up cleanly with Cisco's published product details. Federal agencies in The US are warning that Russian intelligence linked hackers are targeting commercial messaging app accounts in ongoing phishing campaigns. According to a joint FBI and Cybersecurity and Infrastructure Security Agency Alert, the attackers are not hacking the apps themselves. Instead, they're stealing access by tricking users into handing over login credentials, verification codes, or linked device access. Officials say the campaign has already led to unauthorized access to thousands of accounts, which can give attackers access to private messages, contact lists, and in some cases, a way to spread the campaign further using the compromised accounts.
Alex Thomas:Targets include current and former US government officials, military personnel, political figures, journalists, and other high value individuals. Now what makes a story important is how the access occurs. This isn't a case of attackers leveraging a typical vulnerability and defeating encryption on messaging platforms, but rather a case of phishing, social engineering, and eventually account takeover where the user is exploited instead of the app. This is a great reminder that even secure communication tools can still be vulnerable. Links to all the stories we covered today are in the description.
Alex Thomas:Thanks for watching or listening, and we'll see you next week on Wordfence Security News.