BuddyBoss Supply-Chain Hack: The IOC Checklist Every Operator Should Run Today
On March 17, 2026, BuddyBoss's official update server pushed malicious builds of Platform 2.20.3 and Theme 2.19.2 to live customer sites. 309 sites had their databases and Stripe keys exfiltrated. Here is what happened, the indicators of compromise, and the threat-model question every WordPress community owner should be asking by now.