Dec. 1, 2023, 8:10 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

The Wordfence Threat Intelligence Team has recently been informed of a phishing campaign targeting WordPress users. The Phishing email claims to be from the WordPress team and warns of a Remote Code Execution vulnerability on the user’s site with an identifier of CVE-2023-45124, which is not currently a valid CVE. The email prompts the victim to download a “Patch” plugin and install it.



The Download Plugin link redirects the victim to a convincing fake landing page at en-gb-wordpress[.]org:



If …

backdoor campaign claims code code execution cve email fake intelligence phishing phishing campaign phishing scam plugin psa remote code remote code execution scam targeting team threat threat intelligence valid vulnerability wordfence wordpress

Financial Crimes Compliance - Senior - Consulting - Location Open

@ EY | New York City, US, 10001-8604

Software Engineer - Cloud Security

@ Neo4j | Malmö

Security Consultant

@ LRQA | Singapore, Singapore, SG, 119963

Identity Governance Consultant

@ Allianz | Sydney, NSW, AU, 2000

Educator, Cybersecurity

@ Brain Station | Toronto

Principal Security Engineer

@ Hippocratic AI | Palo Alto