A WordPress plugin, PhishWP, is being used by cybercriminals to collect sensitive data such as credit card numbers, CVVs and billing addresses from victims by creating fake payment pages. The plugin’s data is relayed to the attackers in real time via Telegram, with the harvested data used for fraudulent transactions or sold on the dark web. The plugin’s ability to convincingly mimic legitimate payment pages and evade detection makes it particularly dangerous.
HIPAA risk analysis gaps lead to 2 HHS enforcement actions
The HHS Office for Civil Rights (OCR) has settled two ransomware investigations involving Elgon Information Systems and Virtual Private Network Solutions, both found to have