Tech

Thousands of WordPress websites hit in new malware attack, here’s what we know

Share
Share


  • Security researchers find more than 5,000 websites carrying a piece of malicious code
  • The malware installs a plugin that steals login credentials and sensitive data
  • The researchers recommended a number of mitigation measures

Thousands of WordPress websites were observed running malware able to create a rogue admin account and exfiltrated sensitive data through malicious plugins.

A new report from security researcher Himanshu Anand from c/side claims said at least 5,000 WordPress websites were found hosting a malicious script that creates an unauthorized admin account with a username and password that can be found in the code.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Could the ‘Angry Magpie’ save your business from insider threat and data-related attacks?
Tech

Could the ‘Angry Magpie’ save your business from insider threat and data-related attacks?

Browsers are the new frontline, but today’s DLP can’t see the real...

Smart surfaces could represent a powerless solution to multipath signal interference
Tech

Smart surfaces could represent a powerless solution to multipath signal interference

This study demonstrates a passive metasurface technology that uses a time-varying mechanism...

Dual scalable annealing processors overcome capacity and precision limits
Tech

Dual scalable annealing processors overcome capacity and precision limits

The proposed system enables simultaneous expansion of the number of spins and...

All-organic solar cells achieve record efficiency by doubling previous performance
Tech

All-organic solar cells achieve record efficiency by doubling previous performance

Example of damage to the lower layer of a solar cell disposal...