More

    Thousands of WordPress sites targeted with malicious plugin backdoor attacks




    • Security researchers found JavaScript code installing four backdoors to WP-powered sites
    • They also found a vulnerable plugin enabling full website takeover
    • There are patches and mitigations for all these vulnerabilities

    A single piece of JavaScript code deployed no less than four separate backdoors onto roughly 1,000 WordPress websites, according to a new report from cybersecurity researchers c/side, who detailed the four backdoors and explained how website builder users should protect themselves.

    The analysis did not elaborate how the malicious JavaScript made it into these websites – we can assume either weak or compromised passwords, a vulnerable add-on, or similar. In any case, the code is served via cdn.csyndication[dot]com, a domain mentioned in at least 908 websites.

    https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img