#plant


Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Sep 16, 2026 // 11:41

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. “This […]

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Sep 11, 2026 // 10:39

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant […]

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

Aug 11, 2026 // 10:16

Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private […]

Hackers breached a small Polish energy plant via private APN last year

Aug 11, 2026 // 02:16

Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year. The second target […]

Hackers breached a small Polish energy plant via private APN last year

Aug 11, 2026 // 02:16

Hackers used a dedicated mobile gateway to compromise a second facility during the destructive cyberattacks that hit Poland’s energy sector last year. The second target […]

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

Jul 29, 2026 // 19:51

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, […]

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Jul 29, 2026 // 10:50

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content […]

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

Jun 15, 2026 // 22:50

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into […]