Over 5,000 WordPress websites are hosting a malicious script that creates an unauthorized admin account and downloads a harmful plugin, which steals sensitive data and exfiltrates it to a remote server, according to security researcher Himanshu Anand. To combat these attacks, he recommends blocking certain domains, auditing admin accounts, removing suspicious plugins, implementing multi-factor authentication, and strengthening CSRF protections.
Massive malware cleanup.
The FBI has deleted the PlugX malware from thousands of US computers. Meanwhile, researchers have found vulnerabilities in Windows 11, allowing hackers to bypass protections