Golden Finance, reports, Slow Mist Security Alert, recent attackers have exploited WordPress plugin vulnerabilities to attack normal sites, and then injected malicious js code into the site, launching watering hole attacks, popping up malicious pop-ups when users visit the site, deceiving users into executing malicious code or signing Web3 wallets, thus stealing users' assets. It is recommended that sites using WordPress plugins pay attention to troubleshooting whether there are vulnerabilities,...
金色财经 报道,慢雾安全提醒,近期有攻击者利用 WordPress 插件漏洞攻击正常的站点,然后在站点中注入恶意的 js 代码,发起水坑攻击,在用户访问站点时弹出恶意弹窗,骗取用户执行恶意的代码或进行 Web3 钱包签名,从而盗取用户的资产。 建议有使用WordPress插件的站点注意排查是否存在漏洞,及时更新插件,避免被攻击;用户在访问任何站点...