Ancestors

Toot

Written by Lorenzo Franceschi-Bicchierai on 2025-01-29 at 22:09

NEW: Hackers are hijacking several WordPress sites to "spray and pray" Windows and MacOS infostealing malware, according to a cybersecurity firm.

Company says there are thousands of compromised websites and as of yesterday the hacking campaign was “very much live.”

The websites were displaying a fake Chrome browser update page, we saw one of these pages yesterday.

https://techcrunch.com/2025/01/29/hackers-are-hijacking-wordpress-sites-to-push-windows-and-mac-malware/

=> More informations about this toot | More toots from lorenzofb@infosec.exchange

Descendants

Written by Lorenzo Franceschi-Bicchierai on 2025-01-30 at 21:18

We updated the story to include Automattic's comment, which they send today.

https://techcrunch.com/2025/01/29/hackers-are-hijacking-wordpress-sites-to-push-windows-and-mac-malware/

=> View attached media

=> More informations about this toot | More toots from lorenzofb@infosec.exchange

Written by Cybarbie on 2025-01-30 at 00:35

@lorenzofb idk if its related but the wpscanning has been off the charts recently such a pita.

=> More informations about this toot | More toots from nf3xn@mastodon.social

Written by Ryan Boswell 🏳️‍🌈 on 2025-01-31 at 00:13

@lorenzofb Interesting (hands off) position for them to take.

Because I definitely remember security being one of main public facing arguments for Automattic/WordPress.org (or whoever) for eminent domain-ing the Advanced Custom Fields plugin a few months ago.

https://wordpress.org/news/2024/10/secure-custom-fields/

=> More informations about this toot | More toots from ryanboswell@sfba.social

Written by Joe Brockmeier (@jzb) on 2025-01-31 at 03:07

@lorenzofb should “spray and pay” be “spray and pray”?

=> More informations about this toot | More toots from jzb@mastodon.social

Written by Lorenzo Franceschi-Bicchierai on 2025-01-31 at 13:22

@jzb Good catch. Fixed.

=> More informations about this toot | More toots from lorenzofb@infosec.exchange

Written by Joe Brockmeier (@jzb) on 2025-01-31 at 13:40

@lorenzofb My super power is catching other people's typos. My kryptonite is my own typos...

=> More informations about this toot | More toots from jzb@mastodon.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113913924424125234
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
287.670287 milliseconds
Gemini-to-HTML Time
2.341581 milliseconds

This content has been proxied by September (3851b).