Isometric network nodes depicting VPN bypass, admin bug, and botnet takedown.

Daily Cybersecurity News - May 31, 2026

WP Maps Pro Bug Creates Admin Accounts

Hackers are hitting WordPress sites with the WP Maps Pro plugin to add rogue administrator accounts without any login.

The flaw lets unauthenticated users craft requests that create new admins. Public PoC available. It affects versions up to and including 6.1.0 (patched in 6.1.1) of the plugin.

Any WordPress site running the vulnerable plugin is exposed. That includes sites using maps or location features from the plugin.

Attackers already used it on multiple sites to plant backdoors.

Palo Alto VPN Auth Bypass Now Exploited

Palo Alto GlobalProtect VPN has an authentication bypass that attackers are already using to breach corporate networks.

CVE-2026-0257 lets unauthenticated users reach protected portals and gateways. The flaw sits in PAN-OS GlobalProtect handling and carries a high severity rating.

It affects PAN-OS versions before 11.2.4-h4, 11.1.6-h1, 10.2.13-h3 and similar releases on hardware and virtual firewalls used for remote access.

Attackers targeted at least three organizations in the first observed campaigns.

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch police dismantled a botnet that had enslaved millions of devices for attacks.

The operation seized servers and disrupted command infrastructure tied to the network.

This hits the botnet's operational backbone, though its operators remain at large.

The botnet powered distributed denial of service attacks across multiple campaigns.