Hackers Use Nearly 2,000 WordPress Sites for Theft and Ransomware
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Reader view
Choose the default article length.
Software vulnerabilities, dependencies, and application security.
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Five newly fixed WordPress flaws expose conditional paths to admin takeover or server code execution; defenders should verify six component versions and review AJAX and account activity.
Read article →A double-read type confusion lets guest JavaScript corrupt host memory; upgrade isolated-vm 6.x to 6.2.0 or 7.x to 7.0.1.
Read article →Next.js fixed two unauthenticated code-execution paths involving AVIF processing and Windows servers. Self-hosted operators need 15.5.24 or 16.3.3.
Read article →Gitea’s patch API can turn repository content into server code execution. Upgrade to 1.27.2 or later and check server activity for signs of compromise.
Read article →CISA confirmed exploitation of a CVSS 10 Oracle WebLogic proxy flaw. Patch affected Apache and IIS plug-ins, then review requests for unauthorized data access.
Read article →Two exploited miniOrange SAML flaws can mint WordPress admin sessions. Seven independently versioned editions make ordinary update and vulnerability checks unreliable.
Read article →The browser extension exposed vault tokens to untrusted page messages. Version 3.49.6 adds origin, frame, and nonce checks; later builds supersede it.
Read article →Forminator through 1.56.1 trusts forged upload settings and misses dangerous pipe-delimited MIME keys. Update to 1.57.1 and check public upload paths for executable files.
Read article →A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
Read article →A hostile page can rebind its hostname to a Ray dashboard, change Firefox or Safari's User-Agent header, and submit a shell command to the Jobs API.
Read article →Pantheon counted 45 million wp2shell attempts in one week. Defenders should verify current WordPress builds and review exposed sites for persistent access.
Read article →A compromised crates.io account poisoned three Rust packages. Builds ran a downloader; 2,285 arrayref downloads now require cache, lockfile, and host checks.
Read article →