Researchers studying cybersecurity are drawing attention to a dangerous effort that uses malicious JavaScript injections to attack WordPress websites in an attempt to divert people to dubious websites.
In an investigation released last week, Sucuri researcher Puja Srivastava claimed that malware-driven material, such as phony Cloudflare verification, is inserted into websites.
The website security firm claimed that after one of its clients’ WordPress websites displayed questionable third-party JavaScript to site visitors, it launched an investigation and discovered that the attackers had made malicious changes to a file connected to the theme (“functions.php”).
Probably in an effort to avoid discovery, the code added to “functions.php” includes references to Google Ads. However, in practice, it acts as a remote loader by submitting an HTTP POST request read more Hackers Exploit WordPress Sites to Power Next-Gen ClickFix Phishing Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
