News Post

WordPress websites are being hacked to hijack your browser — and then attack other sites


· 3m

Cybercriminals are utilizing compromised WordPress websites to create a vast network for credential stuffing attacks, according to security researchers. The attackers are seeking vulnerable sites to insert a script into their HTML templates, which forces visitors to unknowingly attempt to log in to different WordPress sites using various combinations of usernames and passwords. Once a successful login is achieved, the victim is used to relay the information back to the attackers and receive further instructions. The attackers previously used this technique to install malware, but have now shifted to building a larger base for more destructive attacks.

No Comments yet

Download the medial app to read full posts, comements and news.