Back to news

WordPress Plugin Flaw Leaks API Keys; Android Botnet Tied to Israeli Proxy Firm

Two fresh threats—an actively exploited WordPress vulnerability and a four-year-old botnet linked to a public company—put API credentials and residential network trust at risk.

WordPress Plugin Flaw Leaks API Keys; Android Botnet Tied to Israeli Proxy Firm

What happened

Attackers are actively exploiting CVE-2026-4020, a medium-severity flaw in the Gravity SMTP WordPress plugin, which is active on roughly 100,000 sites. The vulnerability requires no authentication and can expose configuration data, API keys, OAuth tokens, and other secrets stored by the plugin. Separately, researchers at multiple security firms have traced the Popa botnet—an Android-based operation running for at least four years—to NetNut, a residential proxy service operated by the publicly traded Israeli company Ala. The Popa infrastructure has reportedly leveraged millions of compromised consumer TV boxes to conduct advertising fraud, credential-stuffing attacks, and large-scale data scraping.

Why it matters for your business

Any organization running Gravity SMTP should treat unpatched installations as a credential breach in progress: exposed OAuth tokens and API keys can grant attackers access to email infrastructure, payment processors, or third-party SaaS platforms far beyond WordPress itself. The practical step is immediate: apply the vendor patch, rotate any credentials that may have been accessible, and audit plugin configurations for sensitive values stored in plaintext. The Popa botnet story carries a separate but equally pressing lesson—traffic that appears to originate from ordinary residential IP addresses may actually be passing through compromised devices monetized by a legitimate-looking commercial entity, undermining IP-reputation-based fraud defenses. Organizations relying on residential proxy detection to block bots or scraping should recalibrate their threat models accordingly.

What to watch next

Regulatory and legal scrutiny of residential proxy providers is likely to intensify following the public attribution of Popa to a listed company, which could prompt disclosure requirements and enforcement actions that reshape the proxy market. On the WordPress front, security teams should monitor whether threat actors pivot to credential-stuffing or downstream API abuse using keys harvested before patching became widespread. Both stories underscore a broader pattern: infrastructure that appears routine—a popular plugin, a consumer streaming box—is increasingly weaponized at scale.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp