InfoSec News Nuggets 04/13/2026
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers Unknown threat actors gained unauthorized access to Nextend's update infrastructure for the Smart Slider 3 Pro WordPress plugin and distributed a fully attacker-authored build through the official update channel, with any site that updated between its release on April 7, 2026, and detection approximately six hours later receiving a fully weaponized remote access toolkit. The malicious update deployed a sophisticated multi-layered persistence toolkit capable of creating…