Find notable cyber news and cases, enriched with sources, timelines, and signals.

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign
First reported
Last updated
Happening score
H score 89
3 unique sources, 3 articles

Summary

Hide ▲

A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered through the vendor’s CDN and triggered only when a WordPress administrator loaded an infected page. The code created rogue administrator accounts, installed a self-hiding backdoor plugin, and established follow-on access, putting up to 1.2 million websites at risk through the affected install base. Awesome Motive says attackers first reached a marketing server by exploiting a known UpdraftPlus flaw, stole the CDN API key, and then modified distributed JavaScript; the company has since rotated credentials and said its production systems were not breached.

Cases

Related Happenings

PushEngage hit by cyberattack

Incident
H score93 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

How related: WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive's content distribution network (CDN).

About this happening: Awesome Motive's WordPress plugin delivery paths for OptinMonster, TrustPulse, and PushEngage were hit in a CDN supply-chain incident after attackers stole...

Latest development: 15.06.2026 20:37

Awesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key, after attackers exploited a known UpdraftPlus flaw to steal CDN account credentials from a server in its environment and modify JavaScript served from the company's CDN. The company says its application servers, source code, and systems storing OptinMonster and TrustPulse account information were hosted separately and were not breached.

Funnel Builder security patch release (version 3.15.0.3)

Security Patch Release
H score77 First: 16.05.2026 18:20 Last: 16.05.2026 18:20 Sources 1

About this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...

Funnel Builder 3.15.0.3 security update

Security Patch Release
H score74 First: 15.05.2026 22:30 Last: 15.05.2026 22:30 Sources 1

About this happening: FunnelKit released Funnel Builder 3.15.0.3 to fix an actively exploited flaw affecting WordPress/WooCommerce checkout pages, closing a path that could inject malic...

Post SMTP CVE-2025-11833 exploitation wave

Exploitation Wave
H score74 First: 04.11.2025 23:46 Last: 04.11.2025 23:46 Sources 1

About this happening: CVE-2025-11833 in the Post SMTP WordPress plugin is being actively exploited to hijack administrator accounts, putting more than 400,000 sites at risk of full site c...

GutenKit and Hunk Companion actively exploited unauthenticated plugin-install flaws (multiple vulnerabilities)

Vulnerability
H score56 First: 27.10.2025 12:15 Last: 27.10.2025 12:15 Sources 1

About this happening: WordPress sites using GutenKit and Hunk Companion are facing actively exploited plugin-install flaws tracked as CVE-2024-9234, CVE-2024-9707, and CVE-202...

Timeline

  1. 15.06.2026 20:37 1 articles · 1mo ago

    Awesome Motive rotates CDN API key after WordPress CDN compromise

    Mitigation Patch Update

    Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.

    Show sources
  2. 15.06.2026 12:59 3 articles · 1mo ago

    PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

    Initial Disclosure

    On June 12, malicious JavaScript first appeared in OptinMonster and TrustPulse CDN-served files, then persisted longer in PushEngage delivery paths into June 14.

    Show sources