Experts from Sucuri firm have been monitoring attacks on Drupal-based websites leveraging on the CVE-2014-3704 flaw. Thousands of websites were compromised in the months after the disclosure of the flaw (October and November 2014) The most worrisome news is that the cyber attacks remained consistent throughout 2015 and 2016. The experts are warning of a significant increase in SEO spam attacks against Drupal 7 websites. In the vast majority of attacks, hackers have exploited the vulnerability to create new admin accounts on Drupal websites, below attacks trying to force a new admin.”]
Source: https://securityaffairs.co/wordpress/48036/cyber-crime/cve-2014-3704-flaw-drupal.html

