ByteBrief
We're a portrait publication through and through. Turn your phone back and your briefing picks up right where you left it.
(We tried widescreen once. It wasn't us.)
Hackers are mass-exploiting two WordPress Core flaws, dubbed wp2shell, to install webshells and create rogue admin accounts. The critical chain (CVE-2026-63030 and CVE-2026-60137) combines a SQL injection and a REST API route confusion bug, allowing unauthenticated remote code execution. Researcher Adam Kues used OpenAI's GPT-5.6 to develop the exploit in about 10 hours.
Tap to vote and see what everyone thinks.
Summary by ByteBrief