Jan. 15, 2024, 7:45 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Thousands of WordPress sites using a vulnerable version of the Popup Builder plugin have been compromised with a malware called Balada Injector.
First documented by Doctor Web in January 2023, the campaign takes place in a series of periodic attack waves, weaponizing security flaws WordPress plugins to inject backdoor designed to redirect visitors of infected sites to bogus tech

attack backdoor balada balada injector builder called campaign compromised flaws inject injector january malware plugin plugins plugin vulnerability popup security security flaws series version vulnerability vulnerable web wordpress wordpress plugins wordpress sites

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC