Massive attack against 1.6 million WordPress sites underway
Publié le 14 Janvier 2022
Wordfence analysts report having detected a massive wave of attacks in the last couple of days, originating from 16,000 IPs and targeting over 1.6 million WordPress sites.
The threat actors target four WordPress plugins and fifteen Epsilon Framework themes, one of which has no available patch.
Some of the targeted plugins were patched all the way back in 2018, while others had their vulnerabilities addressed as recently as this week.
The affected plugins and their versions are:
- PublishPress Capabilities
- Kiwi Social Plugin
- Pinterest Automatic
- WordPress Automatic
The targeted Epsilon Framework themes are:
- Shapely
- NewsMag
- Activello
- Illdy
- Allegiant
- Newspaper X
- Pixova Lite
- Brilliance
- MedZone Lite
- Regina Lite
- Transcend
- Affluent
- Bonkers
- Antreas
- NatureMag Lite – No patch available
"In most cases, the attackers are updating the users_can_register option to enabled and setting the default_role option to administrator," Wordfence explains.
-
"This makes it possible for attackers to register on any site as an administrator effectively taking over the site."
Check, update, clean
To check if your site has already been compromised, you can review all user accounts and look for any rogue additions that should be removed immediately.
-
Next, review the site's settings at "http://examplesite[.]com/wp-admin/options-general.php" and pay attention to the Membership and the new user default role setting.
It is recommended to update your plugins and themes as soon as possible, even if they're not in the above list. If you're using NatureMag Lite, for which there's no fix, you should uninstall it immediately.
Note that updating the plugins won't eliminate the threat if your site has already been compromised. In this case, you are advised to follow the instructions found in detailed clean-up guides first.
In general, try to keep the number of plugins at your WordPress site to the absolute minimum necessary as this dramatically reduces the chances of being targeted and hacked in the first place.
read more : https://www.bleepingcomputer.com/news/security/massive-attack-against-16-million-wordpress-sites-underway/
Web, Blog : Tendances et chiffres 2020 - OOKAWA Corp. Raisonnements Explications Corrélations
TENDANCES ET CHIFFRES SITES WEB & BLOGS 2020 Il existe plus de 1,60 milliards de sites web dans le monde. Le tout premier site web a été publié le 6 août 1991 par l'informaticien britannique Ti...
http://ookawa-corp.over-blog.com/2021/03/web-blog-tendances-et-chiffres-2020.html
Web, Blog : Tendances et chiffres 2020 - OOKAWA Corp. Raisonnements Explications Corrélations
Cybercrime : les malwares sont désormais disponibles à la location Si vous cherchez à vous introduire dans le système d'une entreprise, à connaître la nouvelle stratégie d'un concurrent ou ...
Cybercrime - Cyber-espionnage - Cybersecurite: les malwares sont désormais disponibles à la location - OOKAWA Corp. Raisonnements Explications Corrélations
4760 cyberattaques en novembre en France - OOKAWA Corp. Raisonnements Explications Corrélations
WatchGuard Threat Lab vient de publier son rapport Threat Landscape avec des statistiques pour la France. Selon le dernier rapport sur les menaces du laboratoire de WatchGuard, la France a subi en ...
http://ookawa-corp.over-blog.com/2020/12/4760-cyberattaques-en-novembre-en-france.html
4760 cyberattaques en novembre en France - OOKAWA Corp. Raisonnements Explications Corrélations
La CISA encourage toutes les organisations impliquées dans le stockage et le transport des vaccins à renforcer leurs protections, notamment pour les opérations de conservation à froid, et à re...
Coronavirus : La chaîne logistique des vaccins visée par des cyberattaques - OOKAWA Corp. Raisonnements Explications Corrélations