WP Fastest Cache plugin bug exposes 600K WordPress sites to attacks

Today, the WPScan team from Automattic disclosed the details of an SQL injection vulnerability, tracked as CVE-2023-6063 and with a high-severity score of 8.6, impacting all versions of the plugin before 1.2.2.

bleepingcomputer.com/news/secu

The U.S. Department of Justice announced today that Federal Bureau of Investigation took down the network and infrastructure of a botnet proxy service called IPStorm.

IPStorm enabled cybercriminals to run malicious traffic anonymously through Windows, Linux, Mac, and Android devices all over the world.

bleepingcomputer.com/news/secu

Security News This Week: US Congress Targeted With Predator Spyware
Plus: Hamas raised millions in crypto, Exxon used hacked data, and more.

wired.com/story/us-congress-sp

Golf gear giant Callaway data breach exposes info of 1.1 million

Sourcegraph website breached using leaked admin access token

Forever 21 data breach: hackers accessed info of 500,000

LogicMonitor customers hacked in reported ransomware attacks

bleepingcomputer.com

Android apps digitally signed by China’s third-biggest e-commerce company exploited a zero-day vulnerability that allowed them to surreptitiously take control of millions of end-user devices to steal personal data and install malicious apps, researchers from security firm Lookout have confirmed.

arstechnica.com/information-te

A bored hacktivist browsing an unsecured airline server stumbled upon national security secrets including the FBI's 'no fly' list. She says what she found reveals a 'perverse outgrowth of the surveillance state.'

businessinsider.com/hacktivist

A new attack method named COVID-bit uses electromagnetic waves to transmit data from air-gapped systems, which are isolated from the internet, over a distance of at least two meters (6.5 ft), where it's captured by a receiver.

The information emanating from the isolated device could be picked up by a nearby smartphone or laptop, even if a wall separates the two.

bleepingcomputer.com/news/secu

42,000 Sites used in

A malicious for-profit group named 'Fangxiao' has created a massive network of over 42,000 web domains that impersonate well-known brands to redirect users to sites promoting adware apps, dating sites, or 'free' giveaways.

Sauce: bleepingcomputer.com/news/secu

Show more

MrGoat🐐🇮🇱🇺🇦

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.