CVE Tools

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

SecurityWeekBy SecurityWeek News

Reported exploitedWordPress Super FormsCyberAv3ngersSIM Swap Infrastructure

Our summary

Threat actors are currently exploiting CVE-2026-14894, a critical vulnerability in the WordPress Super Forms plugin that permits unauthenticated arbitrary file uploads. This flaw allows attackers to deploy PHP webshells, potentially resulting in full control of compromised sites; users should update to version 6.3.314 immediately.

This week’s roundup also details Microsoft’s warning on invisible Unicode characters being used to bypass phishing filters, a US $10 million bounty for IRGC-CEC official Amir Yaryab linked to CyberAv3ngers, and an analysis connecting Chinese group QTFY to military contractors. Additionally, a former AT&T employee was sentenced for facilitating SIM swaps that enabled bank account takeover.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store