CRITICALVulnerability
Global

Russian military hackers pose as recruiters to target Ukrainian IT workers

·Source: The Record

Updated:

Executive Summary

Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.

Analysis

Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
Source Attribution

Originally published by The Record on Aug 10, 2026.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2024-13784 — The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPre...

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no

CVE-2024-13784
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification...

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

CVE-2026-18316
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

CVE-2026-18432
NIST NVD