WordPress Blogs Allegedly Defaced By Hackers
A loophole
in the WordPress blogging software has allowed hackers attack and deface
thousands of sites.
A source revealed that more than 1.5 million
pages on WordPress blogs have been defaced.
The cyber
security firm that found the vulnerability said some hackers were now trying to
use it to take over sites rather than just spoil pages.
WordPress has urged its site owners to update
software to avoid falling victim of the attack.
It was
discovered that, the vulnerability is found in an add-on for the WordPress
blogging software that was introduced in versions released at the end of 2016.
Sucuri (A
security firm) found the severe bug and informed WordPress about it on 20th
January 2017.
WordPress said in a blogpost, that it delayed
going public about the flaw so it could prompt hosting firms to update their
software to a fixed version.
The patched
version of WordPress was formally released on 26 January and led to many sites
and blogs automatically applying the update.
Sucuri said some hacker groups had moved on
from defacement to attempts to use the bug to hijack sites from their own ends.
Sucuri
founder, Daniel Cid said “Attackers are starting to think of ways to monetize
this vulnerability; defacements don’t offer economic returns, so that will
likely die soon.”
Comments