Tagged: WordPress

Kapibala attacker infrastructure map targeting WordPress and Zyxel devices 0

Kapibala Attacker Plunders Government Databases

A solitary IP address, meticulously monitored by GreyNoise since early June, ultimately served as the primary entry point for a massive, multi-pronged cyberespionage campaign. This sophisticated operation simultaneously targeted diverse system classes, including WordPress...

WordPress Click2Shell vulnerability chain forcing a theme install to reach remote code execution 0

Click2Shell: One Link Can Hijack a WordPress Site

A single link in an attacker’s hands can make WordPress install a theme without a button being pressed, provided an already-authenticated administrator opens it. On September 17, WordPress released version 7.1.1, which closes a...