SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, August 30, 2026 INTEL CONFIDENCE 60% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical WordPress Flaws and TerminalFix Campaigns Escalate | CRITICAL |
|
0 C2 IPs | 77 OTX IOCs | 5 ARTICLES |
|
■ ANALYST TLDR A wave of critical vulnerabilities in popular WordPress plugins and themes, including GiveWP and Avada, presents an immediate threat of remote code execution and complete site takeover. Simultaneously, Microsoft has detailed "TerminalFix," a ClickFix-style campaign utilizing fake CAPTCHAs and DLL sideloading to deploy reverse tunnels on target networks. Additionally, toy manufacturer Hasbro has disclosed a data breach exposing employee personal information following a disruptive cyberattack. |
|
■ CRITICAL STORIES Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE Vulnerabilities in widely used plugins like GiveWP, Avada, and TranslatePress allow attackers to bypass authentication and execute arbitrary code, threatening thousands of websites. |
TerminalFix campaign deploys a reverse tunnel through multistage intrusion Attackers are leveraging social engineering via fake CAPTCHAs and DLL sideloading to establish persistent reverse tunnels on target environments. |
Hasbro Data Breach Exposed Employee Personal Information A cyberattack on the toy giant resulted in operational disruptions and the theft of sensitive employee personal data, highlighting ongoing corporate targeting. |
|
■ CVEs IDENTIFIED [CVE-TBD-01] WPMU DEV Dashboard — Authentication Bypass / Account Takeover |
[CVE-TBD-02] Avada Theme — Arbitrary Code Execution (RCE) |
[CVE-TBD-03] TranslatePress — Authentication Bypass |
[CVE-TBD-04] Pods — Arbitrary Code Execution (RCE) |
|
■ THREAT ACTORS TerminalFix Actors | Cybercrime / Initial Access Broker |
Deploying fake CAPTCHAs and DLL sideloading to establish reverse tunnels |
Unknown Threat Actor | Cybercrime / Ransomware |
Breached Hasbro systems, disrupting operations and stealing employee PII |
|
|
|
■ ATT&CK TTPs | T1204.001 | | User Execution: Malicious Link | Users lured by fake CAPTCHA prompts in TerminalFix campaign |
| T1574.002 | | Hijack Execution Flow: DLL Side-Loading | TerminalFix campaign uses DLL sideloading for execution |
| T1021.001 | | Remote Services: Remote Desktop Protocol | Reverse tunnel established to bypass network controls |
| T1190 | | Exploit Public-Facing Application | Exploitation of critical WordPress plugin/theme vulnerabilities |
| T1071.001 | | Application Layer Protocol: Web Protocols | Reverse tunneling and C2 traffic in TerminalFix |
|
■ PATCH PRIORITY GiveWP — Critical flaw allowing Remote Code Execution (RCE) — [THN] |
Avada Theme — Critical flaw allowing Arbitrary Code Execution — [THN] |
Pods — Critical flaw allowing Arbitrary Code Execution — [THN] |
WPMU DEV Dashboard — Critical flaw allowing Authentication Bypass and Account Takeover — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately update WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP plugins/themes to their latest patched versions to prevent RCE and site takeover. |
| 2 | [P1] Deploy endpoint detection rules to identify DLL sideloading behaviors and unauthorized reverse tunnels associated with the TerminalFix campaign. |
| 3 | [P2] Implement web filtering and user awareness training to recognize fake CAPTCHA prompts used by the TerminalFix/ClickFix campaigns. |
| 4 | [P2] Hasbro should conduct comprehensive credential rotation and monitor employee PII for potential identity theft or phishing exploitation. |
| 5 | [P3] Update Brave browser installations to version 1.94 to leverage the new Email Aliases feature for enhanced privacy. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 0 of 0 No C2 IPs today |
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |