Cybersecurity threats are on the rise, with multiple vulnerabilities exposed in recent days. Hackers have been exploiting an unauthenticated information disclosure vulnerability in the Gravity SMTP WordPress plugin, which affects over 100,000 sites. The vulnerability, tracked as CVE-2026-4020, has been addressed in version 2.1.5 of the plugin, but not before hackers made over 17 million attempts to exploit it.
What Happened
In addition to the WordPress plugin vulnerability, the Glassworm botnet, which has been targeting developers in software supply-chain attacks since October 2025, has been disrupted after researchers took down its command-and-control infrastructure. The botnet had been using Solana blockchain transactions and the BitTorrent DHT network to resist conventional disruption efforts.
Meanwhile, the FBI has warned of in-person data theft attacks from the Silent Ransom Group (SRG), which has been targeting U.S.-based law firms. The SRG actors use social engineering schemes to pose as IT support and gain access to company computers, where they can steal data by connecting USB drives or external hard drives.
Why It Matters
These cybersecurity threats highlight the evolving nature of attacks and the need for organizations to stay vigilant. The exploitation of the WordPress plugin vulnerability demonstrates the importance of keeping software up to date, while the disruption of the Glassworm botnet shows the effectiveness of coordinated efforts to take down malicious infrastructure.
The FBI's warning about in-person data theft attacks from the SRG also emphasizes the need for organizations to be aware of social engineering schemes and to educate their employees on how to spot and report suspicious activity.
Key Facts
- Who: Hackers, Glassworm botnet operators, Silent Ransom Group (SRG)
- What: Exploitation of WordPress plugin vulnerability, disruption of Glassworm botnet, in-person data theft attacks
- Impact: Over 100,000 sites affected by WordPress plugin vulnerability, Glassworm botnet disrupted, SRG attacks targeting law firms
What Experts Say
"The cybersecurity industry has evolved significantly over the past 20 years, from perimeter defense to AI-native security." — Cybersecurity expert
Key Numbers
- 100,000: Number of sites affected by WordPress plugin vulnerability
- 17 million: Number of attempts to exploit WordPress plugin vulnerability
- 400: Number of software artifacts impacted by Glassworm botnet attack in March
- 4: Number of days given to U.S. federal agencies to patch actively exploited cPanel plugin flaw
Background
The cybersecurity industry has undergone significant changes over the past 20 years, with a shift from perimeter defense to AI-native security. As threats continue to evolve, organizations must stay informed and take proactive measures to protect themselves.
What Comes Next
As cybersecurity threats continue to escalate, organizations must remain vigilant and take steps to protect themselves. This includes keeping software up to date, educating employees on social engineering schemes, and staying informed about the latest threats.