WordPress ships an urgent patch, a payroll-email scam walks past two-factor codes, and a five-year-old flaw drains $130M from 'offline' bitcoin wallets
WordPress released a security update worth installing today
WordPress 7.0.3 landed on August 6 and fixes eleven security issues at once. The one drawing attention needs no account and no password: a flaw on the login screen that an attacker can trigger before signing in, which in the wrong circumstances can be walked forward into running code on the site itself. The release announcement says plainly that this is a security release and "it is recommended that you update your sites immediately", and notes the fixes are being backported to every branch still eligible for them — currently as far back as 4.7. A technical write-up puts the severity at 8.9 out of 10 and reports no evidence of exploitation in the wild as of August 7. Turning the flaw into code execution takes an extra step that depends on tricking a logged-in administrator, which is exactly the part you cannot rely on not happening. Why it matters: WordPress runs a large share of small-business websites, and a public security release is also a public map for anyone who wants to attack sites that have not applied it. Log in to your site's dashboard today and confirm it reads 7.0.3 (or 7.1). If automatic background updates are switched on, it may already be done — check rather than assume, because sites on managed hosting, sites with a customized update policy, and sites left on an older major version often are not covered. If someone else maintains the site for you, this is a one-line email worth sending now.
A phishing campaign is taking over Microsoft 365 accounts to read payroll and invoice email
Security researchers have documented a campaign that starts with a routine voicemail notification email and ends with someone else sitting quietly inside a company's Microsoft 365 account. The fake sign-in page sits between the victim and the real Microsoft login, passing everything through — which means it captures the password and the six-digit code, so having two-factor turned on does not stop it. The Hacker News describes the redirect chain and what the attackers did afterward: rather than sending obvious scam messages, they searched the organization for the people who handle payroll, HR, finance and administration, and read the message threads about payroll runs, invoices and payments. In some cases they added a mailbox rule that moved certain incoming messages straight to Deleted Items and marked them read, so the person who should have noticed never saw them. Targets have included healthcare, education, manufacturing, government and professional services organizations in the US, Canada and Europe. A parallel write-up of two 2026 attack chains describes the same end goal — real email threads used to redirect a payment. Why it matters: the payoff here is a payment that goes to the wrong bank account, sent by a real person acting on a real-looking email thread. Two things are worth doing this week. First, check your mailbox rules — in Outlook, Settings → Mail → Rules — and delete any you did not create, then have anyone who touches invoices or payroll do the same. Second, make one rule absolute: any change to bank details, however convincing the thread it arrives in, is confirmed by phone on a number you already had, never a number in the message.
A flaw in 'offline' bitcoin wallets has cost owners more than $130 million
Hardware wallets are sold on the promise that keys made on a device that never touches the internet cannot be guessed. A defect in how certain Coldcard devices generated recovery phrases broke that promise: the phrases were predictable enough to work out, and thieves have been emptying the wallets ever since. TechCrunch reported losses above $130 million as of August 4, with the underlying code dating to 2021. The manufacturer's own advisory names the affected versions — Mk2 and Mk3 on firmware 4.0.1 through 4.1.9, Mk4 and Mk5 seeds made before 5.6.0, and Q before 1.5.0Q — and says funds are at risk where the phrase was generated without dice rolls and the wallet has no strong passphrase. Its instruction is to install the fixed firmware first, generate a new phrase, verify the backup, send a small test transaction, and only then move the rest. A second wave is now chasing the same owners: emails claiming a "coordinated security audit" of the device network, with an August 10 deadline, lead to a file that installs remote-control software on the victim's computer. Why it matters: if you hold cryptocurrency on one of these devices, the money is only safe once it sits behind a phrase generated on patched firmware — read the manufacturer's advisory on its own site and follow its order of operations. And treat every message about this as hostile: a real manufacturer responding to a key-generation flaw publishes firmware, not an emailed audit that asks you to download and run something.
Microsoft Edge has started switching off older extensions, ad blockers included
Edge has begun retiring extensions built on the older Manifest V2 format, the same transition Chrome went through. Some well-known content and ad blockers are built that way, and the versions that survive the change can filter less than they used to. Microsoft's announcement sets out the schedule: the change starts in the Canary, Dev and Beta channels and broadens to the regular Stable version over the following months, with the consumer transition targeted for completion by the end of 2026 and work-managed devices unaffected until early 2027. "Over the next few months, MV2 extensions will be gradually turned off by default," it says, with users notified in advance and pointed to updated versions where one exists. Microsoft says 95% of the most-used extensions in its store have already moved over, leaving 58 with meaningful usage that have not. Why it matters: most people will notice this as an extension that stopped working, or ads that started appearing on sites that were quiet for years — not as a scheduled change. When the notice appears, take the recommended replacement from the browser's own extensions page rather than searching for a lookalike, because moments like this are when convincing fake extensions get installed. If a blocker you depend on has no replacement, decide deliberately whether to switch browsers or accept the change; both are fine, and finding out in December is worse than deciding now.
Google Maps will now order your food and book your hotel
Maps' built-in assistant has picked up the ability to finish the task instead of just listing options. Ask it for a specific dish nearby and it will assemble an order and hand you to the restaurant's ordering platform to check out; ask for a hotel and it will compare prices and availability before sending you to a booking site. Google's own post says food ordering is rolling out with Square and Toast, with Uber Eats coming later, and that the assistant adds the dish to your cart so you can "review and complete your order" in the restaurant's own system. TechCrunch adds the rest of the rollout detail: food ordering, hotel booking and event tickets are US-only for now, and the assistant can draw on your Gmail and Calendar to personalize answers where you have granted that permission. Why it matters: for anyone running a restaurant, hotel or venue, this quietly changes who your listing has to satisfy. The customer may never open your website — an assistant reads your Maps profile and your ordering platform, then decides whether you make the shortlist. Open your own business profile this week and check the parts a machine reads: current hours, an up-to-date menu with real dish names, and whether your online ordering is connected through a platform Maps can actually hand a customer to. For everyone else, the useful habit is to look at the final price on the partner's own page before confirming, since the assistant is handing you off rather than completing the purchase itself.