![WordPress wp2shell and ServiceNow AI Flaws Under Active Attack [Prime Cyber Insights]](https://img.transistorcdn.com/ndFViyMFOnk1Bv4KhEA65e_ME2ItUoE5M4s7ybsSYfY/rs:fill:0:0:1/w:1400/h:1400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hZjNh/Y2IwZDQ3NzM2ZDkz/MDdkZTgzOGRhNDEz/NjExYy5wbmc.jpg)
This episode analyzes the exploitation of WordPress vulnerabilities and critical flaws in ServiceNow's AI Platform, along with discussions on malware and ransomware threats.
This briefing analyzes the surge in exploitation of the WordPress 'wp2shell' vulnerability chain, where CVE-2026-63030 and CVE-2026-60137 allow for unauthenticated remote code execution. Security researchers report that AI-assisted analysis made developing these exploits trivial, leading to widespread scanning and over 100 backdoor administrator accounts created. We also examine a critical sandbox escape flaw in ServiceNow's AI Platform, tracked as CVE-2026-6875, which is currently seeing in-the-wild exploitation. Beyond enterprise software, the episode covers the 'ClickLock' macOS stealer, a malicious tool that locks systems until a user surrenders their password, and the 'Bit2Watt' research from Zhejiang University illustrating how GPU workloads could be weaponized to destabilize power grids. Finally, we look at the Qilin ransomware group's recent shift toward exploiting legacy Palo Alto GlobalProtect vulnerabilities to achieve domain-wide encryption. This episode provides practitioners with the technical context needed to prioritize patching for these high-impact entry points.
Organizations: WordPress, ServiceNow, Zhejiang University, Qilin
Products: ClickLock, Bit2Watt, Palo Alto GlobalProtect
Explore listener stats, chart rankings, contacts and more on the Neural Newscast podcast page.