PhishWP Plug-in Hijacks WordPress e-Commerce Checkouts

PhishWP Plug-in Hijacks WordPress e-Commerce Checkouts

A malicious plug-in discovered on a Russian cybercrime discussion board turns WordPress websites into phishing pages by creating faux on-line cost processes that convincingly impersonate trusted checkout companies. Masquerading as reputable e-commerce apps resembling Stripe, the malware proceeds to steal buyer cost information. Known as PhishWP, the WordPress plug-in was designed by Russian cybercriminals to…

Read More
U.S. Military Soldier Arrested in AT&T, Verizon Extortions – Krebs on Safety

U.S. Military Soldier Arrested in AT&T, Verizon Extortions – Krebs on Safety

Federal authorities have arrested and indicted a 20-year-old U.S. Military soldier on suspicion of being Kiberphant0m, a cybercriminal who has been promoting and leaking delicate buyer name data stolen earlier this 12 months from AT&T and Verizon. As first reported by KrebsOnSecurity final month, the accused is a communications specialist who was lately stationed in…

Read More
Fortinet warns of malicious Python packages focusing on credentials and consumer knowledge

Fortinet warns of malicious Python packages focusing on credentials and consumer knowledge

A brand new report out at this time from Fortinet Inc.’s FortiGuard Labs is warning of two newly found malicious Python packages that pose a excessive danger of credential theft, knowledge exfiltration and unauthorized system entry. The primary vulnerability, Zebo-0.1.0, was discovered to exhibit subtle malware conduct, together with obfuscation methods to cover its performance…

Read More
Contained in the wild fall and last-minute revival of Bench, the VC-backed accounting startup that imploded over the vacations

Contained in the wild fall and last-minute revival of Bench, the VC-backed accounting startup that imploded over the vacations

Friday, December 27, was purported to be the beginning of a soothing vacation weekend. However it was chaos for hundreds of small enterprise homeowners who use Bench, an accounting and tax startup based mostly in Canada that raised $113 million from buyers like Bain Capital Ventures and Shopify. That morning, they discovered themselves unable to…

Read More
China-Linked Cyber Risk Group Hacks US Treasury Division

China-Linked Cyber Risk Group Hacks US Treasury Division

A Chinese language-state-sponsored cyberattack compromised the U.S. Treasury, having access to labeled paperwork by a vulnerability by third-party cybersecurity supplier BeyondTrust. The breach, revealed on Dec. 31, underscores the rising sophistication of state-backed cyber espionage efforts. “Treasury takes very critically all threats towards our programs, and the information it holds,” a division spokesperson stated in…

Read More