This past week was a reminder of how varied today's threat landscape really is. A critical RCE surfaced right in WordPress core, which WordPress put out with forced updates. The SonicWall SMA VPN appliance was being exploited as a zero-day for weeks before disclosure, and the Inc ransomware group used it to reach root.
Alongside that, a new trend showed up: the NadMesh botnet is deliberately hunting exposed AI tools and stealing cloud keys from them. The human layer stays the weak spot, with ACR Stealer spreading through ClickFix, where the victim launches the attack themselves. And the Qilin ransomware group posted around 32 victims in this week alone, which puts the whole roundup into perspective.