Threat Vectr Weekly — week of Aug 24
Stories covered this week
Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of thousands of WordPress sites at risk of full takeover.
SafePal Discloses Breach Hitting Nearly 40,000 Wallet Customers
A flaw in the crypto hardware wallet maker's systems exposed order records for 39,798 buyers, and a criminal is now advertising the stolen data for sale.
France's tax office admits hackers walked off with data on 678,000 people
A criminal listed the stolen database for sale on a hacking forum in August. The French finance ministry now says property records and tax figures were among the files taken.
IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.
New Zealand's spy agency says China is spying 'at scale'. Beijing says that's a lie.
New Zealand's national intelligence service named China as the only country conducting large-scale espionage on its soil. China's embassy fired back, calling the report fabricated and blaming 'anti-China forces' for orchestrating the claims.
Criminals Spent Almost $7 Million Buying Expired Web Domains to Push Scams and Malware
Infoblox says 50,400 'dropcatch' domains were scooped up in the first half of 2026 to inherit the trust of the sites that came before them.
Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit
Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar, Mongolia and Pakistan.
NHS Transplant Service Sent Patients' Private Medical Data Over an Open Radio Network for Years
NHS Blood and Transplant used a pager system that broadcast donor names, birth dates and organ-matching scores without any encryption, meaning anyone with basic radio equipment could have been listening.
Transcript
Narrated by two AI anchors. Lightly formatted for reading.
Welcome to Threat Vectr Weekly for the week of August 24th. I'm Marcus, and we have a packed episode for you today. Eight stories, and they run the gamut — a critical flaw quietly sitting inside more than half a million WordPress sites, a French tax authority learning about its own breach from a hacker forum, and the NHS admitting it broadcast transplant patients' private medical records over an open radio network for years. Elena's here with me as always, and we're going to move fast, so let's get into it.
We start with a vulnerability that should have every WordPress site owner checking their dashboard right now. A widely used plugin called Forminator Forms — it's the kind of tool that lets you drop a contact form or a quiz onto your site without writing a line of code — has been found to carry a flaw rated 9.8 out of 10 on the Common Vulnerability Scoring System. That scale goes to 10, so this is about as bad as it gets. The vulnerability is tracked as CVE-2026-15748, and here's why it's so alarming: an attacker who has never created an account on your site can upload a booby-trapped PHP file through the plugin and make your web server execute it. Once that happens, they can read your database, plant a backdoor, or take over the site entirely. More than 600,000 WordPress sites use this plugin. The fix is straightforward — update Forminator immediately — and while you're at it, scan your upload folders for any files you don't recognize. Elena, over to you.
Thanks, Marcus. From a compromised plugin to a compromised supply chain of trust. SafePal makes hardware wallets — those small physical devices that store cryptocurrency offline, away from the internet. The whole pitch is security, which makes this breach land especially hard. The company has told customers that an attacker found a flaw in one of its systems and used it to pull down order records for roughly 39,798 people. The stolen data includes names, shipping addresses, phone numbers, email addresses, and details of exactly what each person ordered. A criminal is now advertising that data for sale on an underground forum, first reported by BleepingComputer. SafePal is being clear that wallet secrets — the private recovery phrases that actually unlock the coins — live only on the device itself and were not touched. But everything that was taken is still a real problem. If you know someone bought a hardware crypto wallet, you know they likely hold cryptocurrency, and you have a very targeted audience for phishing attacks and fake support calls. If you're a SafePal customer, be skeptical of any message that claims to be from the company right now.
Are you at risk? It takes one wrong click, on one bad email, to bring a whole company down. Train2Secure turns your staff from your biggest risk into your strongest defence, with realistic phishing simulations and quick security training that actually sticks. From $1.59 per user, per month, cheaper than a single cup of coffee. Start your free trial at Train2Secure dot com. That's Train, the number two, Secure, dot com.
Staying on the theme of stolen databases, France's tax authority just had a rough few weeks. The General Directorate of Public Finances — known in France as the DGFiP — is the country's equivalent of the IRS, and it's now confirmed that attackers made off with records on 678,000 individuals and businesses. Here's the part that stings: the ministry didn't discover this on its own. A user on a hacking forum called PwnForums, going by the handle ZeroBytes, listed the database for sale on August 12th. BleepingComputer reported it, and only then did the tax office start digging. What was in the files? Tax income figures, family quotient data, withholding rates, company names, French business registration numbers called SIREN IDs, and property details from the national land registry. Passwords and online account credentials were apparently not included, so existing account access is intact. The ministry says affected people will be contacted by email or letter starting next week. But the lesson here is hard to ignore — a government agency learned about its own breach from a criminal advertisement. That is a significant failure in detection.
Marcus, that story connects to something we hear from security teams constantly — organizations discovering they have a problem only when the data shows up somewhere public. A lot of that comes back to the next topic, which is identity and access management, or IAM. It's a bit of an inside-baseball term, but the core idea is simple: IAM is the set of systems that decide who can log in to what, and what they're allowed to do once they're inside. Compliance in this area used to mean producing a policy document, a spreadsheet of user reviews, and a few screenshots for the auditor. Regulators have gotten a lot more skeptical of that approach. Frameworks like SOX, HIPAA, PCI DSS 4.0, and GDPR all require access controls, but increasingly, auditors want continuous, timestamped evidence that those controls are working on a random Tuesday, not just during the audit window. One area that catches organizations off guard: non-human identities. Service accounts, API keys, machine tokens — these now outnumber human users at most large organizations, and they fall under the same rules. Stale accounts and failed access reviews remain the most common audit findings across every framework. If your organization hasn't looked at who — or what — still has access to things it shouldn't, that's where to start.
Now to geopolitics, and a story that's both significant and, in some ways, not surprising. New Zealand's Security Intelligence Service — the NZSIS, roughly the country's equivalent of the FBI's counterintelligence division — released its fourth annual Security Threat Environment report this week, and it named China, by name, in a public document, as the only country conducting espionage inside New Zealand at serious scale. The report also called China the most active foreign government attempting to interfere with New Zealand's politics and institutions. That kind of public attribution is unusual. Intelligence agencies generally prefer to keep that kind of accusation classified. Making it in a published report is a deliberate diplomatic statement. China's embassy in Wellington rejected the findings completely, calling them baseless and fabricated, and suggested the report itself might be a product of foreign interference by unnamed international forces. New Zealand is a member of the Five Eyes intelligence alliance alongside the US, UK, Canada and Australia — all of which have made similar public statements about Chinese espionage in recent years. Elena, this one's yours to pick up.
It really does feel like a pattern, Marcus. And while nation-state hacking gets the headlines, the next story is about a quieter, more financially motivated operation that affects all of us whenever we search the web. Researchers at Infoblox — a company that monitors the internet's address system for signs of abuse — tracked 50,400 expired domain names that criminals bought up in just the first half of 2026. They spent close to seven million dollars doing it. The tactic is called dropcatching. When a website owner stops paying for a domain name, the name eventually becomes available again. Criminals monitor that moment and register the domain the instant it drops. The payoff is that an old domain comes with baggage — in a good way for the attacker. It may have years of inbound links, a trusted reputation with search engines, and email addresses that recipients recognize. Visitors who click an old bookmark or a search result land on a scam page or get served malware, all while thinking they're at a site they've used before. There's no binding federal rule targeting dropcatching specifically yet, though regulators are pressing domain registrars for stronger buyer verification. For now, the practical advice is simple: be cautious any time a familiar-looking site asks you to do something unexpected.
From expired domains to hidden malware. Kaspersky researchers have published findings on a new campaign from a Chinese state-linked hacking group tracked under several names, most commonly Mustang Panda or HoneyMyte. The group has been active for years, and it's just upgraded its toolkit in a significant way. They're deploying an updated version of a backdoor called CoolClient — a program that gives the attackers remote control over an infected machine, letting them run commands, steal files, and surveil the system. But what's new and particularly troubling is what they've paired it with: a Windows rootkit that operates at the kernel level, the deepest layer of the operating system. This rootkit hides files, processes, registry entries, and network traffic from security software. And here's the detail that makes defenders' jobs harder — the rootkit carries a valid digital signature, meaning Windows sees it as a trusted piece of software and loads it without complaint. Confirmed victims so far are in Myanmar, Mongolia, and Pakistan. This is a sophisticated, well-resourced operation, and the signed rootkit means many standard detection tools will simply miss it. Over to you, Elena, for our final story.
Marcus, this last one is genuinely hard to believe, and I say that as someone who covers this space every week. NHS Blood and Transplant — the UK body responsible for matching organ donors with recipients — has admitted that it broadcast sensitive transplant patient data over an unencrypted pager network for an unspecified number of years. Unencrypted means the signal was readable in plain text by anyone with basic radio equipment tuned to the right frequency. The intercepted data included donor names, recipient dates of birth, organ types, tissue-match scores, and immunosuppression risk ratings. To be clear, that is some of the most sensitive medical information a person can have. A BBC investigation broke the story, and it also found hundreds of unencrypted messages from ambulance trusts and hospitals covering mental health incidents, medication details, and at least one patient's suicide attempt. The UK government told the NHS to phase out pagers by 2021. Parts of the health service never did. NHSBT has now stopped sending patient data via pagers and reported the breach to the Information Commissioner's Office, the UK's data-protection regulator. The lesson, uncomfortable as it is, is that legacy technology doesn't quietly retire itself. Someone has to actively decommission it, and when that doesn't happen, the consequences can be serious.
That is a story that should spark some hard conversations in every organization still running legacy communication systems — not just in healthcare. Elena, thank you, as always. And thank you to everyone listening to Threat Vectr Weekly this week. Eight stories, and the through-line across almost all of them is the same: known risks, delayed action, and consequences that arrive before the fixes do. We'll be back next week with another full briefing. In the meantime, head over to threatvectr dot com slash newsletter to get all of this in your inbox, with links to the source reporting and our analyst notes. Stay sharp out there. If you got something out of this, a thumbs up and a subscribe genuinely helps.
