A curated dispatch from GajShield

The GajShield Gazette

Lead story

BdThemes plugins supply-chain hack creates rogue WordPress admins

BdThemes Supply-Chain Attack Shows How Remote Content Can Turn Trusted WordPress Plugins into BackdoorsThe supply-chain compromise affecting the BdThemes WordPress plugin ecosystem demonstrates how attackers can compromise thousands of websites without modifying the softwa…

Also today
In brief

LexisNexis shuts down services after suspicious activity on servers

LexisNexis Service Shutdown Highlights the Security Risk Created by Third-Party Hosted InfrastructureLexisNexis’ decision to take several i…

Aug 10, 2026

Critical Progress LoadMaster flaw now actively exploited in attacks

CISA Warning on Actively Exploited Progress LoadMaster Flaw Highlights the Growing Risk Around Edge InfrastructureCISA’s warning that attac…

Aug 10, 2026

How a simple request for AI to book a gym class exposed a major threat

AI Assistant’s Gym Website Hack Shows Why Autonomous Agents Need Security Boundaries, Not Just InstructionsThe reported incident in which a…

Aug 10, 2026

Suisun City Declares State of Emergency After Cyberattack | KQED

Suisun City Cyberattack Shows Why Municipal Cybersecurity Is Now a Public Safety IssueThe cyberattack that forced Suisun City, California, …

Aug 10, 2026

Framework's Data Breach Revealed Customer Data: Here's What to Know - CNET

Framework Data Breach Shows Why Analytics Platforms Can Become High-Value Targets for Customer Data TheftThe data breach affecting Framewor…

Aug 10, 2026

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New CSS Attacks Show How a Malicious Email Can Break Out of the Message and Attack the Webmail InterfaceNew research into the security of H…

Aug 09, 2026

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase Zero-Day Exploitation Shows Why Analytics Platforms Must Be Treated as Privileged Data InfrastructureThe active exploitation of a …

Aug 09, 2026

Hackers breach TrueConf to trojanize client installers with backdoors

Nearly 800 Malicious npm Packages Show How Software Dependencies Are Becoming Malware Delivery InfrastructureThe discovery of hundreds of m…

Aug 09, 2026

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Nearly 800 Malicious npm Packages Show How Software Dependencies Are Becoming Malware Delivery InfrastructureThe discovery of hundreds of m…

Aug 08, 2026

CISA Adds One Known Exploited Vulnerability to Catalog

CISA Adds Actively Exploited Progress LoadMaster RCE to KEV CatalogCISA’s addition of CVE-2026-8037 to its Known Exploited Vulnerabilities …

Aug 08, 2026

Unlimited Technology Systems breach impacts 3.8 million people

Unlimited Technology Systems Breach Exposing 3.8 Million Patients Highlights the Growing Risk of Healthcare Data ConcentrationThe data brea…

Aug 08, 2026