Get a Pentest and security assessment of your IT network.

Cyber Security

Criminals Monetizing Attacks Against Unpatched WordPress Sites

Sites still vulnerable to a severe REST API endpoint flaw in WordPress are now being targeted by attackers trying to turn a profit. The vulnerability was silently patched in the recent 4.7.2 security update. Researchers at SiteLock estimate that some 20 attackers are vying for these illicit dollars. The attackers are taking advantage of websites running on the WordPress platform that have not yet updated to the most recent version. The issue lies in the way the REST API manages access by favoring values such as GET and POST rather than existing values.

Source: https://threatpost.com/criminals-monetizing-attacks-against-unpatched-wordpress-sites/123848/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security