Hackers Exploit Gravity SMTP Plugin Bug to Expose API Keys

Malicious hackers are racing to exploit a vulnerability in the Gravity SMTP plugin, which has been installed on around 100,000 WordPress sites, to get their hands on sensitive API keys. Over 17 million exploit attempts have already been blocked by Wordfence, highlighting the urgent need for site owners to update to version 2.1.5.

https://osintsights.com/hackers-exploit-gravity-smtp-plugin-bug-to-expose-api-keys?utm_source=mastodon&utm_medium=social

#Wordpress #GravitySmtp #Cve20264020 #InformationDisclosure #RestApi

Hackers Exploit Gravity SMTP Plugin Bug to Expose API Keys

Learn how hackers exploit the Gravity SMTP plugin bug to expose API keys and protect your site now with expert security tips and immediate action steps.

OSINTSights

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites

A critical bug in the Gravity SMTP plugin is being exploited by hackers on over 100,000 WordPress sites, putting sensitive information at risk. Update to version 2.1.5 or later to patch the vulnerability.

https://osintsights.com/hackers-exploit-gravity-smtp-plugin-bug-on-100000-wordpress-sites?utm_source=mastodon&utm_medium=social

#Wordpress #Smtp #GravitySmtp #Cve20264020 #PluginVulnerability

Hackers Exploit Gravity SMTP Plugin Bug on 100,000 WordPress Sites

Protect your WordPress site from Gravity SMTP plugin bug exploitation; learn how to secure your site now and prevent information disclosure vulnerabilities effectively today.

OSINTSights
🤔 Ah, the classic "same client" saga with CVE-2026-4020—because who needs originality in #hacking when you have a Google Cloud fleet playing dress-up with 3,299 user agents? 🌍📬 Apparently, exploiting Gravity #SMTP is a team sport, but only if your team is a single IP address with a personality disorder. What a performance! 🎭💻
https://honeylabs.net/blog/the-cloud-fleet-behind-cve-2026-4020 #CVE20264020 #GoogleCloud #SecurityFlaw #Cybersecurity #HackerNews #ngated
Most of the CVE-2026-4020 attackers are the same client | HoneyLabs blog

Almost every IP we logged exploiting the Gravity SMTP credential bug shares one HTTP fingerprint. Behind it is a Google Cloud fleet of thousands of short-lived instances, disguised by 3,299 rotating user-agents, sweeping more than 36,000 ports for .env files, git configs, credentials, and database dumps.

HoneyLabs
Most of the CVE-2026-4020 attackers are the same client | HoneyLabs blog

Almost every IP we logged exploiting the Gravity SMTP credential bug shares one HTTP fingerprint. Behind it is a Google Cloud fleet of thousands of short-lived instances, disguised by 3,299 rotating user-agents, sweeping more than 36,000 ports for .env files, git configs, credentials, and database dumps.

HoneyLabs