Tag: content management system (CMS)

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors
News

WooCommerce Users Targeted by Fake Patch Phishing Campaign Deploying Site Backdoors

A widespread phishing campaign that targets WooCommerce customers by posing as a security alert and asking them to download a "critical patch" but really deploying a backdoor is being warned about by cybersecurity researchers. The activity, according to WordPress security firm Patchstack, was clever and a variation of a different operation that was noticed in December 2023 and used a phony CVE trick to compromise websites using the well-known content management system (CMS). The most recent attack wave is thought to be either the work of the same threat actor or a new cluster that closely resembles the previous one due to the similarities in the phishing email lures, the fake websites, and the identical techniques used to hide the malware read more about WooCommerce Users Targeted b...
WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables
News

WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables

Researchers studying cybersecurity are alerting people to a new, covert credit card skimmer effort that inserts malicious JavaScript code into a database table linked to the content management system (CMS) in order to target WordPress e-commerce checkout pages. According to a recent analysis by Sucuri researcher Puja Srivastava, this credit card skimmer virus targets WordPress websites by covertly inserting malicious JavaScript into database records to capture private payment information. The malware only activates on checkout pages, where it either inserts a phony credit card form or takes over the payment fields that are already there read more about WordPress Skimmers Evade Detection by Injecting Themselves into Database Tables. Get up to date on the latest cybersecurity news ...