Website Security News

Sucuri Blog Learn about website security, software vulnerabilities, how to protect WordPress, and malware infections from our team of security researchers.

  • JavaScript Malware Switches to Server-Side Redirects & DNS TXT Records as TDS
    by Denis Sinegubko on April 18, 2024 at 6:51 pm

    Last August we documented a malware campaign that was injecting malicious JavaScript code into compromised WordPress sites to redirect site visitors to VexTrio domains. The most interesting thing about that malware was how it used dynamic DNS TXT records of the tracker-cloud[.]com domain to obtain redirect URLs. We’ve been tracking this campaign ever since — and we’ve recorded multiple changes in obfuscation techniques and domain names used in their DNS TXT traffic direction system (TDS). Continue reading JavaScript Malware Switches to Server-Side Redirects & DNS TXT Records as TDS at Sucuri Blog.

  • WordPress Maintenance: Tasks & Best Practices
    by Rianna MacLeod on April 16, 2024 at 8:23 pm

    If you’re managing a WordPress site, it’s crucial to ensure it runs smoothly and securely. Many site owners worry that WordPress maintenance is a complex chore that requires a ton of technical expertise, but that’s not entirely true. This guide is here to show you the steps you can take on your own to help maintain your WordPress site and keep it running at its best. Think of your WordPress site like a car. Continue reading WordPress Maintenance: Tasks & Best Practices at Sucuri Blog.

  • Credit Card Skimmer Hidden in Fake Facebook Pixel Tracker
    by Matt Morrow on April 11, 2024 at 4:57 pm

    In recent months, we have encountered a number of cases where attackers inject malware into website software that allows for custom or miscellaneous code — for example, the miscellaneous scripts area of the Magento admin panel, or WordPress plugins such as Custom CSS & JS. Custom script editors are popular with bad actors because they allow for external third party (and malicious) JavaScript and can easily pretend to be benign by leveraging naming conventions that match popular scripts like Google Analytics or libraries like JQuery. Continue reading Credit Card Skimmer Hidden in Fake Facebook Pixel Tracker at Sucuri Blog.

  • Web Shells: Types, Mitigation & Removal
    by Cesar Anjos on April 8, 2024 at 8:11 pm

    Web shells are malicious scripts that give attackers persistent access to compromised web servers, enabling them to execute commands and control the server remotely. These scripts exploit vulnerabilities like SQL injection, remote file inclusion (RFI), and cross-site scripting (XSS) to gain entry. Once deployed, web shells allow attackers to manipulate the server, leading to data theft, website defacement, or serving as a launchpad for further attacks. Given their stealth and versatility across various programming languages (PHP, Python, Ruby, ASP, Perl, Bash), web shells pose a significant threat to a website’s security. Continue reading Web Shells: Types, Mitigation & Removal at Sucuri Blog.

  • Magento Shoplift: Ecommerce Malware Targets Both WordPress & Magento CMS
    by Puja Srivastava on April 2, 2024 at 8:09 pm

    We often write about malware that steals payment information from sites built with Magento and other types of e-commerce CMS. However, WordPress has become a massive player in ecommerce as well, thanks to the adoption of Woocommerce and other plugins that can easily turn a WordPress site into a fully-featured online store. This popularity also makes WordPress stores a prime target — and attackers are modifying their MageCart ecommerce malware to target a wider range of CMS platforms. Continue reading Magento Shoplift: Ecommerce Malware Targets Both WordPress & Magento CMS at Sucuri Blog.

  • WordPress Vulnerability & Patch Roundup March 2024
    by Sucuri Malware Research Team on March 25, 2024 at 5:29 pm

    Vulnerability reports and responsible disclosures are essential for website security awareness and education. Automated attacks targeting known software vulnerabilities are one of the leading causes of website compromises. To help educate website owners about potential threats to their environments, we’ve compiled a list of important security updates and vulnerability patches for the WordPress ecosystem this past month. The vulnerabilities listed below are virtually patched by the Sucuri Firewall and existing clients are protected. Continue reading WordPress Vulnerability & Patch Roundup March 2024 at Sucuri Blog.

  • Sign1 Malware: Analysis, Campaign History & Indicators of Compromise
    by Ben Martin on March 20, 2024 at 6:38 pm

    A new client recently came to us reporting seemingly random pop ups occurring on their website. While it was clear that there was something amiss with the website it was difficult to reproduce the issue. However, by inspecting our server side scanner logs we were able to locate the source of the unwanted behavior — and it turned out to be a remarkably interesting JavaScript injection related to a massive malware campaign that we internally call Sign1. Continue reading Sign1 Malware: Analysis, Campaign History & Indicators of Compromise at Sucuri Blog.

  • What is .htaccess Malware? (Detection, Symptoms & Prevention)
    by Ben Martin on March 15, 2024 at 9:21 pm

    The .htaccess file is notorious for being targeted by attackers. Whether it’s using the file to hide malware, redirect search engines to other sites with black hat SEO tactics, or inject content — the range of possibilities for misuse is vast, making it a prime target for hackers. .htaccess malware can be hard to pinpoint and clean up since it allows an attacker to make multiple changes to the web server and its behavior. Continue reading What is .htaccess Malware? (Detection, Symptoms & Prevention) at Sucuri Blog.

  • Sucuri WordPress Plugin Updates for 2024
    by Rianna MacLeod on March 13, 2024 at 7:26 pm

    At Sucuri, we believe in making the internet safe for everyone. One way we show this is through our free WordPress security plugin. The Sucuri WordPress plugin is available for download in the WordPress repository. It comes with a range of security features, including WordPress hardening, malware scanning, core integrity check, post-hack features and email alerts to help keep your website protected. This year, we’re rolling out a number of new features and enhancements to help improve your plugin experience and strengthen your website’s security — all free of charge. Continue reading Sucuri WordPress Plugin Updates for 2024 at Sucuri Blog.

  • New Malware Campaign Found Exploiting Stored XSS in Popup Builder < 4.2.3
    by Puja Srivastava on March 7, 2024 at 5:31 pm

    In January, my colleague reported about a new Balada Injector campaign found exploiting a recent vulnerability in the widely-used Popup Builder WordPress plugin which was initially disclosed back in November, 2023 by Marc Montpas. In the past three weeks, we’ve started seeing an uptick in attacks from a new malware campaign targeting this same Popup Builder vulnerability. According to PublicWWW, over 3,300 websites have already been infected by this new campaign. Our own SiteCheck remote malware scanner has detected this malware on over 1,170 sites. Continue reading New Malware Campaign Found Exploiting Stored XSS in Popup Builder < 4.2.3 at Sucuri Blog.

  • From Web3 Drainer to Distributed WordPress Brute Force Attack
    by Denis Sinegubko on March 5, 2024 at 9:15 pm

    Two weeks ago we discussed a new development in website hacks: Web3 crypto wallet drainers. We’ve been closely following the most significant variant which injects drainers using the external cachingjs/turboturbo.js script. Our SiteCheck website scanner has already detected this version on over 1,200 sites since the beginning of February, 2024. Since our last post, this malware campaign has seen two new iterations resulting in distributed brute force attacks against target WordPress websites from the browsers of completely innocent and unsuspecting site visitors. Continue reading From Web3 Drainer to Distributed WordPress Brute Force Attack at Sucuri Blog.

Websitecyber related posts:

Avast Cybersecurity News

Avast Cybersecurity News and Information.

Cyber Warfare

RAND Research Topic Cyber Warfare

The World’s Most Secure Buildings

From underground military bunkers and gold reserves to historic and rarely accessed religious archives, we've unlocked the world’s most secure buildings.

Navy Cyber Competition

Learn how these Sailors are testing their skills through competition to help the combat today's cyber threats.

Webinars Sucuri

Webinars Sucuri Complete Website Security, Protection & Monitoring

Australian Charities Cyberattack

Thousands of charity donors have had their personal details leaked, in a cyberattack. The hackers published some information.

Hacking The Japan Times

Hacking The Japan Times News on Japan, Business News, Opinion, Sports, Entertainment and More

Cyber Attack Group Down By FBI

A criminal ransomware network connected to a cyber attack at some of Connecticut’s hospitals has been taken down by the FBI.

Internet of Things Security

Ken Munro shows us how insecure Internet of Things products are and how easy it is to hack them.

Ransomware Attack on AIIMS Server

There has been a ransomware attack on AIIMS server. European Parliament's website has been attacked too. Is the world prepared to fight a cyber war?

How a Teenager Hacked Uber

Going over what's currently known about the major Uber breach, and how the hacker was able to compromise the entire Uber network in very little time.

Optus Data Breach CEO Kelly Bayer Rosmarin

The CEO of Optus says she'll take full accountability for the data hack that's left more than 9 million customers exposed.
Share Websitecyber