Threat hunters have identified a rogue WordPress plugin capable of creating fake administrator users and injecting malicious JavaScript code to steal credit card information. The plugin, part of a Magecart campaign targeting e-commerce sites, replicates itself into must-use plugins, conceals its presence, and also includes an option to create hidden admin accounts. The campaign’s objective is to inject credit card-stealing malware into checkout pages and transmit the data to a hacker-controlled domain.
Safaricom-Backed M-TIBA Victim of a Possible Data Breach Affecting Millions of Kenyans
Linet Amuli reports: Kenya’s digital health sector is facing a major cybersecurity crisis after hackers claimed to have stolen a massive trove of personal and

