Hackers Use Nearly 2,000 WordPress Sites for Theft and Ransomware
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Reader view
Choose the default article length.
Page 4 of 10
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Shadowserver's retrospective Dysphoria report identifies about 296,000 compromised IoT devices and gives network owners evidence to locate and rebuild affected systems.
Read article →Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
Read article →A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
Read article →CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Read article →Citrix documents denial of service. Separate research demonstrates a SAML path to root code execution but has not confirmed that it maps to this CVE.
Read article →An exposed server revealed a repeatable Active Directory attack path, AI-assisted planning, Aurora lockers, and payment trails across multiple victims.
Read article →ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Read article →Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →Dindoor uses the signed Deno runtime, encoded stages, and a pre-persistence sandbox check. Hunt the fixed process and registry sequence beneath the changing payload.
Read article →Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
Read article →CareCloud says forensic review confirmed patient data exfiltration. HHS reports 3.76 million affected people, while public records do not map specific fields to each person.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
Read article →An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
Read article →A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →