A curated dispatch from GajShield

The GajShield Gazette

Lead story

Funnel Builder WordPress plugin bug exploited to steal credit cards

The active exploitation of the Funnel Builder WordPress plugin is a serious warning for WooCommerce site owners because this is not just a website defacement risk, it directly targets payment data. The flaw affects plugin versions before 3.15.0.3 and can be abused without auth…

Also today
In brief

Stealer Backdoor Found in 3 Node-IPC Versions Targeting Developer Secrets

The malicious Node-IPC versions are another sharp reminder that open-source package repositories are now part of the enterprise attack surf…

May 15, 2026

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

The active exploitation of CVE-2026-42897 in on-premises Microsoft Exchange Server is a serious reminder that email platforms remain one of…

May 15, 2026

OpenAI confirms security breach in TanStack supply chain attack

The OpenAI incident linked to the TanStack “Mini Shai-Hulud” supply-chain attack is another reminder that developer environments have becom…

May 15, 2026

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited i…

May 15, 2026

TeamPCP hackers advertise Mistral AI code repos for sale

The TeamPCP claim around Mistral AI repositories shows how software supply-chain attacks are now moving beyond package poisoning into sourc…

May 15, 2026

Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin

The active exploitation of the Burst Statistics WordPress plugin vulnerability shows how quickly attackers weaponize flaws in widely deploy…

May 15, 2026

Dell confirms its SupportAssist software causes Windows BSOD crashes

Dell confirming that SupportAssist Remediation version 5.5.16.0 is causing Windows BSOD crashes is a reminder that endpoint management and …

May 14, 2026

PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure

The PraisonAI CVE-2026-44338 authentication bypass is a clear warning for the fast-growing AI agent ecosystem. The vulnerability affects Pr…

May 14, 2026

KongTuke hackers now use Microsoft Teams for corporate breaches

KongTuke’s shift to Microsoft Teams for corporate breaches shows how attackers are moving their social engineering directly into trusted bu…

May 14, 2026

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

The 18-year-old NGINX rewrite module vulnerability, tracked as CVE-2026-42945 and named “NGINX Rift,” is a serious reminder that even matur…

May 14, 2026

New Fragnesia Linux flaw lets attackers gain root privileges

The Fragnesia Linux kernel vulnerability, tracked as CVE-2026-46300, is another serious reminder that local privilege escalation flaws can …

May 14, 2026