Skip to main content

Week 8: Malware on WordPress

Recently, researchers announced that more than 2000 websites running WordPress are infected with Malware. WordPress is an open source software used to create websites for a variety of items. "The malware in question logs passwords and just about anything else an administrator or visitor types."
This is the second time in a matter of month this particular malware was found on WordPress sites. The first time it was found on 5, 500 sites back in December of 2017. This was remediated when the site used to host the scripts was taken down. At this point, these new cases have no connection to the previous incidents as these malicious scripts are found on three new sites.
"Attackers inject the cdjs[.]online script into either a site's WordPress database (wp_posts table) or into the theme's functions.php file, as was the case in the December attack that used the cloudflare[.]solutions site. Sinegubko also found the cdns[.]ws and msdns[.]online scripts injected into the theme's functions.php file. Besides logging keystrokes typed into any input field, the scripts load other code that causes site visitors to run JavaScript from Coinhive that uses visitors' computers to mine the cryptocurrency Monero with no warning." (Goodin, 2018)
It appears these incidents are allowing the scripts due to the lack of maintenance on the sites. According to the researchers for these cases, many of the sites are simply not using current software. "Rate shows that there are still many sites that have failed to properly protect themselves after the original infection," (Goodin, 2018) This goes to show one must always ensure they have the latest software in order to protect them and any other folks who might be visiting their site

References:


Goodin, D. (2018, January 29). More than 2,000 WordPress websites are infected with a keylogger. Retrieved February 05, 2018, from https://arstechnica.com/information-technology/2018/01/more-than-2000-wordpress-websites-are-infected-with-a-keylogger/

Comments

Popular posts from this blog

Week 6: Spectre and Meltdown Fallout Continues.

By this time, many of you have heard about the Spectre and Meltdown vulnerabilities of which a lot of machines are susceptible. Most of the major parties involved have provided fixes through various patching means. However, there is still significant fallout due to this gap. Intel is now reporting their firmware patch is causing updates on some of the new chips they have produced. "Firmware updates were causing problems with Ivy Bridge, Sandy Bridge, Skylake and Kaby Lake." (Schwartz, 2018) This flaw is causing frequent reboots and instability in those chips. Additionally, Intel is behind in getting their firmware updates to the various vendors. Some of the major brands which are affected by these gaps are still feeling their way around this and trying to ensure they patch appropriately. It is likely we will see higher than normal OS updates for most folks when it comes to their computers, tablets, and smartphones. However, the big concern and part of the reason this g...

Week 2 Blog: Apple's Recent Software Security Issues

Recently, my favorite tech company has been in the news for some very significant security gaps in their applications. Apple has long been branded as very secure software. Frequently, people will say they just don't get a virus. However, there was a security gap that impacted the Macs, which were using their latest software - High Sierra. This vulnerability allowed root access to any machine running this software. Various sites such as "The Verge" indicate using root to access these machines allow elevated privileges on the machine. It could be used to change Apple ID emails as well as user passwords. The gap presented a huge dent in Apple's reputation on security. Part of it was the way it was announced- the person who discovered the vulnerability publicly disclosed it on twitter. Interesting enough, Apple has a bug detection program in which they pay for any gaps in their software. Even more recently, a new vulnerability was discovered in Apple's Home Kit...

What is leadership anyways?

Security Leadership is what precisely? I ask the question because it is a concept I am wrestling with at this time. What does it mean to be a security leader? Is it merely leading a security department as an information security manager or at the enterprise level as a chief information security officer or chief security officer? Is it influencing an organization's security posture without having an official title? Ultimately, leadership is about people. They said leadership is about getting people to work toward a common goal. The question is, are folks in those roles business leaders who are leading a technical portfolio, or are they technical leaders who enable the business to accomplish their goals? It is likely security leaders are both, and often need to be both. They're technical leaders and business leaders. However, they require different leadership skills to be successful. The additional factor is what is the senior leadership need from their senior security...