A WordPress plugin, PhishWP, is being used by cybercriminals to collect sensitive data such as credit card numbers, CVVs and billing addresses from victims by creating fake payment pages. The plugin’s data is relayed to the attackers in real time via Telegram, with the harvested data used for fraudulent transactions or sold on the dark web. The plugin’s ability to convincingly mimic legitimate payment pages and evade detection makes it particularly dangerous.

Italian ship stopped in France: had malware on board, two people arrested – Il Sole 24 ORE
Italian ship stopped in France: had malware on board, two people arrested Il Sole 24 ORE

.webp?w=0&resize=0,0&ssl=1)
