cognitive cybersecurity intelligence

News and Analysis

Search

Over 6,000 WordPress hacked to install plugins pushing infostealers

Hackers are breaching WordPress sites to install malicious plugins, which push information-stealing malware through the display of fake software updates and errors. Since 2023, the ClearFake and the subsequent 2024 ClickFix campaigns have been the primary vehicles for these attacks. Recently, GoDaddy reported that over 6,000 WordPress sites have been breached to run these fake alert campaigns. The culprits gain access through stolen admin login credentials. To counter these threats, plugin audits and password resets are advised.

Source: www.bleepingcomputer.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts