More than 500 websites that used a free analytics service inadvertently exposed their visitors to a nasty malware attack made possible by a hack of PageFair, the anti-adblocking company that provided the analytics. . The compromise started in the last few minutes of Halloween with a spearphishing e-mail that ultimately gave the attackers access to PageFair's content distribution network account. The attacker then reset the password and replaced the JavaScript code PageFair normally had execute on subscriber websites. For almost 90 minutes after that, people who visited 501 unnamed sites received popup windows telling them their version of Adobe Flash was out-of-date and prompting them to install malware disguised as an official update. . An intrusion orchestrated through a breached data analysis platform affected over 400 websites, leveraging a deceitful email campaign to spread malicious software.. Malware Attack, Web Security Threats, PageFair Incident. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.