MEDIUMSupply Chain
Global

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

·Source: The Hacker News

Updated:

Executive Summary

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Analysis

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Indicators of Compromise (1)

Domain (1)
WordPress.org
Source Attribution

Originally published by The Hacker News on Aug 11, 2026.

Related Threats

MEDIUMSupply Chain

Securing Software at the Speed of AI: What Four Years of Data Reveal

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/securing-software-at-the-speed-of-ai-what-four-years-of-data-reveal" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/AI%20ERA%20SOFTWARE%20ASSEMBLY%20BLOG.png" alt="Image with statistics and text regarding AI software assembly" class="hs-featured-image" style="width:auto !important; max

Sonatype (Maven/npm)
HIGHSupply Chain

OpenAI president’s blog pushing agentic AI most notable for what it did not say

OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant flaws, and defenders need to find and fix them before attackers do.” He added: “The Hugging Face incident showed that we un

CSO Online
MEDIUMSupply Chain

US FCC Weighs Chinese Transceiver Supply-Chain Crackdown

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-fcc-weighs-chinese-transceiver-supply-chain-crackdown-image_small-2-a-32584.jpg" align=right hspace=4><b>Draft Covered List Expansion Would Reach Components Inside AI Data Center Switches</b><br>The U.S. FCC reportedly may restrict imports of new-model optical transceivers made in China, a move that would reach AI data center i

Bank Info Security