The WordPress plugin WP Statistics, which has an active installation base of 500k users, has an unauthenticated stored XSS vulnerability on versions prior to 12.6.7.…
A long-lasting malware campaign (1,2) targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites. As…
We recently found this malware on a windows hosting server where the web.config file was modified with the following code. The code redirects multiple user…
The domain en-google-analytic[.]com, currently sinkholed by a security intelligence company, has been observed by our team to be part of a mass spam injection campaign.…
During a recent investigation we found this suspicious code pretending to be associated with Bing ads.After further review, we see that the code is actually…