Hackers Use Nearly 2,000 WordPress Sites for Theft and Ransomware
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →Reader view
Choose the default article length.
Endpoint security, malware, device controls, and host visibility.
StopAndProtect turns hacked WordPress sites into malware hosts, command servers, and stores for stolen files before selective ransomware deployment.
Read article →CISA says attackers are exploiting a Linux IPv6 kernel flaw that can give a local user root and, on affected RHEL 10 systems, escape a container.
Read article →ErrTraffic lures lead users to run Cruciferra, which uses a vulnerable signed driver to terminate security processes before the Remus stealer runs.
Read article →Dindoor uses the signed Deno runtime, encoded stages, and a pre-persistence sandbox check. Hunt the fixed process and registry sequence beneath the changing payload.
Read article →A new Windows loader arrives through a fake Teams help desk; modules sent to Expel’s emulator phish passwords and tunnel into internal services.
Read article →An updated Android banking trojan blocks Google Play traffic, automates wireless ADB pairing, and targets 349 financial apps across 16 countries.
Read article →A 1.1 MB fake installer delivers Vidar, launches installed browsers headlessly, and copies credentials and sessions that can remain useful after cleanup.
Read article →Kaspersky traced malware on DoFun-powered car displays from a trusted updater to ad fraud and a residential proxy. DoFun says it fixed the issue but published no fixed build.
Read article →C2Looper shifted from one-second HTTP beacons to GitHub C2. Hunt its OneDrive DLL, JSON control files, debug marker, commands, hashes, and two IPs.
Read article →Check Point reproduced kernel file and registry operations through Defender's signed BTR.sys driver. Abuse needs admin rights; behavioral telemetry separates it from cleanup.
Read article →Patch the missing upload check, then audit who can still reach the three remaining weaknesses in the Configuration Manager exploit chain.
Read article →CISA says attackers are exploiting a Windows IKE remote-code flaw; verify April fixed builds and restrict UDP 500 and 4500 until every exposed host is patched.
Read article →CISA now ties CVE-2025-60710 to ransomware. The local Windows flaw needs an existing foothold, then lets an attacker elevate to SYSTEM.
Read article →