In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Reported exploitedWordPress Super FormsCyberAv3ngersSIM Swap InfrastructureOur summary
Threat actors are currently exploiting CVE-2026-14894, a critical vulnerability in the WordPress Super Forms plugin that permits unauthenticated arbitrary file uploads. This flaw allows attackers to deploy PHP webshells, potentially resulting in full control of compromised sites; users should update to version 6.3.314 immediately.
This week’s roundup also details Microsoft’s warning on invisible Unicode characters being used to bypass phishing filters, a US $10 million bounty for IRGC-CEC official Amir Yaryab linked to CyberAv3ngers, and an analysis connecting Chinese group QTFY to military contractors. Additionally, a former AT&T employee was sentenced for facilitating SIM swaps that enabled bank account takeover.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.