A malware concealed in a WordPress caching plugin can create administrative accounts for websites, allowing threat actors to take over infected sites. Researchers from Wordfence found the harmful plugin, which acts as either a standalone script or a plugin and offers remote plugin activation and content filtering capabilities. To stay protected, WordPress users should adhere to security best practices and employ security monitoring for their sites.
![](https://healsecurity.com/wp-content/uploads/2024/06/1718009491_ticketmaster-data-breach-and-rising-work-from-home-scams-1524x512.jpg)
Mobile Indian Cyber Heist: FatBoyPanel And His Massive Data Breach
The zLabs research team discovered a mobile malware campaign targeting Indian bank users. The malware is being distributed through WhatsApp and collects a user’s sensitive