Dec. 7, 2023, 1:45 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

On December 6, 2023, WordPress rolled out version 6.4.2, addressing a vulnerability introduced in version 6.4 – specifically, a POP chain issue within the core. This vulnerability depended on the existence of an additional PHP Object Injection vulnerability. Simply put, coupled with any other Object Injection vulnerability that may exist in a plugin, it presented a critical threat, potentially enabling arbitrary PHP code execution on websites. Wordfence emphasizes this risk, underscoring the potential for a complete site takeover.


Simultaneously, a …

alerts backdoor campaign december injection issue latest object phishing phishing campaign php pop takeover version vulnerability wordpress

Digital Security Infrastructure Manager

@ Wizz Air | Budapest, HU, H-1103

Sr. Solution Consultant

@ Highspot | Sydney

Cyber Security Analyst III

@ Love's Travel Stops | Oklahoma City, OK, US, 73120

Lead Security Engineer

@ JPMorgan Chase & Co. | Tampa, FL, United States

GTI Manager of Cybersecurity Operations

@ Grant Thornton | Tulsa, OK, United States

GCP Incident Response Engineer

@ Publicis Groupe | Dallas, Texas, United States