BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
NERF
The Vault
Threat Actors
Privacy Threats
Malware IoC
Dashboard
CVEs
Tags
Intel
NERFThe VaultThreat ActorsPrivacy ThreatsMalware IoCDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /European Commission Breached, FBI Director's Email Compromised, WordPress Plugin Flaw Affects 500K Sites

European Commission Breached, FBI Director's Email Compromised, WordPress Plugin Flaw Affects 500K Sites

highMalware & Threats|March 30, 20262 min read

Originally reported by BleepingComputer, Malwarebytes Labs

#data-breach#wordpress#vulnerability#iran-apt#shinyhunters#european-commission#fbi#smart-slider
Share

TL;DR

High-profile breaches hit the European Commission and FBI Director Patel's personal email, while a Smart Slider WordPress plugin vulnerability threatens 500,000 sites with arbitrary file access.

Why high?

Multiple high-profile breaches including European Commission and FBI Director's personal email by Iranian threat actors, combined with a WordPress plugin vulnerability affecting 500K sites.

Security Roundup: High-Profile Breaches and Critical Plugin Vulnerability

A series of significant security incidents emerged this week, highlighted by breaches of major government entities and a widespread WordPress vulnerability affecting half a million sites.

European Commission Confirms Data Breach After ShinyHunters Attack

The European Commission acknowledged a data breach following a cyberattack on its Europa.eu web platform, according to BleepingComputer reporting. The ShinyHunters extortion gang claimed responsibility for the compromise, marking another high-profile target for the notorious cybercriminal group.

The breach represents a significant security incident given the European Commission's role as the executive arm of the European Union. Details regarding the scope of compromised data and the attack vector remain under investigation.

Iranian-Linked Hackers Compromise FBI Director's Personal Email

The FBI confirmed that Handala hackers, associated with Iranian threat actors, successfully breached FBI Director Kash Patel's personal email account. The attackers published photos and documents obtained from the compromise, demonstrating their access to sensitive communications.

This incident highlights the persistent targeting of high-ranking U.S. officials by Iranian cyber operations, extending attacks beyond official government systems to personal accounts of key leadership figures.

Smart Slider WordPress Plugin Vulnerability Affects 500,000 Sites

Security researchers identified a critical vulnerability in the Smart Slider 3 WordPress plugin that allows subscriber-level users to access arbitrary files on affected servers. The flaw impacts over 500,000 of the plugin's 800,000+ active installations.

The vulnerability represents a significant privilege escalation issue, enabling low-privilege users to potentially access sensitive server files including configuration data and credentials. Website administrators should immediately update the plugin to address this security gap.

Microsoft Withdraws Problematic Windows Update

Microsoft pulled the KB5079391 Windows 11 non-security preview update due to widespread installation errors. Users reported encountering 0x80073712 error codes during the update process, prompting Microsoft to withdraw the release for investigation.

While not a security issue, the problematic update deployment demonstrates the ongoing challenges in enterprise patch management and the importance of testing update rollouts before widespread distribution.

Weekly Security Summary

Malwarebytes Labs published their weekly security roundup covering developments from March 23-29, providing additional context on emerging threats and security trends during this active period for cyber incidents.

Sources

  • https://www.bleepingcomputer.com/news/security/european-commission-confirms-data-breach-after-europaeu-hack/
  • https://www.bleepingcomputer.com/news/security/fbi-confirms-hack-of-director-patels-personal-email-inbox/
  • https://www.bleepingcomputer.com/news/security/file-read-flaw-in-smart-slider-plugin-impacts-500k-wordpress-sites/
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-pulls-windows-kb5079391-update-over-0x80073712-install-errors/
  • https://www.malwarebytes.com/blog/news/2026/03/a-week-in-security-march-23-march-29

Originally reported by BleepingComputer, Malwarebytes Labs

Tags

#data-breach#wordpress#vulnerability#iran-apt#shinyhunters#european-commission#fbi#smart-slider

Threat Actors

🏴ShinyHunters

Related Intelligence

  • Nation-State Roundup: Iran-linked Handala Targets FBI Director, ShinyHunters Breaches EU Commission, Apple Warns of Active Web Exploits

    highMar 29, 2026
  • Threat Intelligence Digest: Chinese APT Campaign, Critical Router RCE, and Agent Tesla Resurgence

    highFeb 26, 2026
  • Weekly Threat Roundup: Government Breaches, Geopolitical Wiper Attacks, and Mass Data Exposures

    highMar 24, 2026

Related Knowledge

  • NERF Deep Training: Malware Analysis, Reverse Engineering, and Evasion Techniques

    offensive
  • Malware Analysis Deep Dive — NERF Training Module

    dfir
  • DFIR & Threat Hunting Deep Training — NERF Knowledge Base

    dfir

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← TeamPCP Supply Chain Attack Targets Telnyx Python SDK Users

Next Article

Critical Infrastructure Under Fire: Fortinet RCE, Russian iOS Exploits, and NetScaler Memory Leaks→