X
WordPress plugin suite hacked to push malware to thousands of sites
Mark Anderson | Security | April 17, 2026

Euclid Security Newsletter

April 17, 2026 

WordPress plugin suite hacked to push malware to thousands of sites

More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them.

 

Security News

New Microsoft Defender "RedSun" zero-day PoC grants SYSTEM privileges

This exploit is for a local privilege escalation (LPE) flaw that grants SYSTEM privileges in Windows 10, Windows 11, and Windows Server on the latest April Patch Tuesday patches, when Windows Defender is enabled.

"Your shipment has arrived" email hides remote access software

An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool-an ideal starting point for attackers to explore a network, steal data, and drop additional malware.

Recently leaked Windows zero-days now exploited in attacks

Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions.

Open source malware sees a 21% increase

A new report from Sonatype identifies 21,764 malicious open source packages in the first quarter of the year, up 21 percent from the same period last year and bringing the total logged since 2017 to 1,346,867.

Microsoft: Some Windows servers enter reboot loops after April patches

Microsoft has confirmed that some Windows domain controllers are entering restart loops due to Local Security Authority Subsystem Service (LSASS) crashes after installing the April 2026 security updates.

Google wipes out 602 million scam ads with Gemini

Malvertising remains an ongoing issue on Google's ad network, with attackers abusing paid ads to pose as legitimate brands and lure users into malware downloads or phishing sites.

 

Important Updates & Patches

Microsoft April 2026 Security Updates

Microsoft's April 2026 Patch Tuesday provides security updates for 167 flaws, including 2 zero-day vulnerabilities, and addresses eight "Critical" vulnerabilities, 7 of which are remote code execution flaws and the other is a denial of service flaw.

Cisco Releases Security Updates

Cisco has released security updates to patch four critical vulnerabilities, including a fixed improper certificate validation flaw in the company's cloud-based Webex Services platform that requires further customer action.

 

Dan's Corner

Google Chrome's vertical tabs are here

Vertical tabs are one of those must-have features that can help you juggle all your open web pages. Both Firefox and Microsoft Edge have long offered them. And now Google Chrome has officially joined the party.

 

An archive of Euclid Security Newsletters can be found on the support website.

Euclid Technology Solutions, LLC
540 Devall Drive, Suite 301
Auburn, AL 36832

P: 301-657-8089
E: support@euclidtechnology.com

Email sent to [EMAIL]

New Comment ...

Sort by: