Collected every two hours from specialised publications — each link leads to the original article.
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malwar…
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) p…
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release …
A financially motivated threat actor codenamed UNC5142 has been observed abusing blockchain smart contracts as a way to facilitate the distribution of informat…
WordPress 6.8.3 Release Security updates included in this release: A data exposure issue where authenticated users could access some restricted content. Indepe…
A new large-scale campaign has been observed exploiting over 100 compromised WordPress sites to direct site visitors to fake CAPTCHA verification pages that em…
A now-removed GitHub repository that advertised a WordPress tool to publish posts to the online content management system (CMS) is estimated to have enabled th…
Heads up, WordPress admins! Researchers ask WordPress users to update their sites with the latest…Patch These Compromised WordPress Plugins Asap To Avoid Attac…
Cybersecurity researchers have discovered a previously undocumented malware targeting Android devices that uses compromised WordPress sites as relays for its a…
Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.First documente…
Cybersecurity researchers have shed light on a new sophisticated strain of malware that masquerades as a WordPress plugin to stealthily create administrator ac…
Users of Advanced Custom Fields plugin for WordPress are being urged to update version 6.1.6 following the discovery of a security flaw.The issue, assigned the…
Over one million WordPress websites are estimated to have been infected by an ongoing campaign to deploy malware calledBalada Injectorsince 2017.The massive ca…
WordPress sites are being targeted by a previously unknown strain of Linux malware that exploits flaws in over two dozen plugins and themes to compromise vulne…
The new Capoae Go malware, which targets WordPress installs and Linux systems, highlights the increase of cyberattacks designed to deploy cryptocurrency-mining…
Hackers are exploiting various websites to conduct phishing attacks. These websites redirect users to fake sites prompting a malicious ChromeMany Users Hacked …
A popular WordPress theme plugin with over 200,000 active installations contains a severe but easy-to-exploit software vulnerability that, if left unpatched, c…
Attention WordPress users!Your website could easily get hacked if you are using "Ultimate Addons for Beaver Builder," or "Ultimate Addons for Elementor" and ha…
According to statistics, WordPress accounted for 90% of hacked CMS sites in 2018. WordPress is a favorite for website owners,Top Reasons Why WordPress Sites Ge…
The malware known as GootLoader has resurfaced yet again after a brief spike in activity earlier this March, according to new findings from Huntress.The cybers…
A serious code execution vulnerability compromised the security of the GiveWP WordPress plugin, risking thousands…GiveWP Plugin Vulnerability Risked 100,000+ W…
Threat actors are leveraging manipulated search results and bogus Google ads that trick users who are looking to download legitimate software such as WinSCP in…
Threat actors have been observed serving malicious code by utilizing Binance's Smart Chain (BSC) contracts in what has been described as the "next level of bul…
A financially-motivated malware campaign has compromised over 800 WordPress websites to deliver a banking trojan dubbed Chaes targeting Brazilian customers of …