fbpx
Sunday, May 19, 2024
WordPress plugin installed on 1 million+ sites logged plaintext passwords

WordPress plugin installed on 1 million+ sites logged plaintext passwords

Getty Images All-In-One Security, a WordPress security plugin installed on more than 1 million websites, has issued a security update after being caught three weeks ago logging plaintext passwords and storing them in a database accessible to website admins. The passwords were logged when users of a site using the plugin, typically abbreviated as AIOS,…
A security scientist with an animosity is dropping Web 0days on innocent users

A security scientist with an animosity is dropping Web 0days on...

0
Over the past three weeks, a trio of critical zeroday vulnerabilities in WordPress plugins has exposed 160,000 websites to attacks that allow criminal hackers to redirect unwitting visitors to malicious destinations. A self-proclaimed security provider who publicly disclosed the flaws before patches were available played a key role in the debacle, although delays by plugin…

Recent Posts