Attackers have hijacked thousands of websites running the WordPress content management system and are using them to infect unsuspecting visitors with potent malware exploits, researchers said Thursday. . The campaign began 15 days ago, but over the past 48 hours the number of compromised sites has spiked, from about 1,000 per day on Tuesday to close to 6,000 on Thursday, Daniel Cid, CTO of security firm Sucuri, said in a blog post. The hijacked sites are being used to redirect visitors to a server hosting attack code made available through the Nuclear exploit kit, which is sold on the black market. The server tries a variety of different exploits depending on the operating system and available apps used by the visitor. . Surge in compromised WordPress websites utilized for malicious software attacks impacting users.. WordPress Exploits, Malware Threats, Website Attack, Security Incident. . LinuxSecurity.com Team
One in every 24 Googlebots is a imitation spam-flinging denial of service villain that masquerades as Mountain View to sneak past web perimeter defences, according to security chaps at Incapsula. Villains spawn the "evil twins" to hack and crack legitimate websites and form what amounted to the third most-popular type of DDoS attack to scourge the internet.. Incapsula detected 50 million unwanted visits by the fake bots which made up four percent of all legitimate Googlebot HTTPS user-agents. The link for this article located at The Register UK is no longer available. . Incapsula detected 50 million unwanted visits by the fake bots which made up four percent of all leg. every, googlebots, imitation, spam-flinging, denial, service, villain, masquerades. . LinuxSecurity.com Team
Anonymous hackers associated with the AntiSec movement have downed at least 70 law enforcement websites. The hackers also managed to extract "massive amounts" of confidential documents, including email spools, usernames, social security numbers, residential addresses, phone numbers, password dumps, classified documents, internal training files and informant lists. . "The leaked data contains jail inmate databases and active warrant information. [However], we [will be] redacting the name/address info to demonstrate how those facing the gun of the criminal injustice system are our comrades and not adversaries," AntiSec explained in an official communiqu The link for this article located at TG Daily is no longer available. . Unidentified cybercriminals targeted governmental sites, exposing private information such as detainee documents and correspondence.. Anonymous Hacking, Data Breach, Law Enforcement Attack, Cyber Security Threats, AntiSec Movement. . Alex
The massive attack managed to inject the name of several rogue domains into hundreds of thousands of websites. The link led to a page that carried out a fake virus scan and then recommended fake security software to clean up what it supposedly found.. But despite the huge success by the attackers, swift action by security firms looks to have limited the number of victims. The link for this article located at BBC News is no longer available. . But despite the huge success by the attackers, swift action by security firms looks to have limited . massive, attack, managed, inject, rogue, domains, hundreds, thousands. . LinuxSecurity.com Team
The M&G Online website is now offline in the wake of an attack by Russian hackers. The Mail & Guardian Online, one of South Africa. Mail & Guardian editor Nic Dawes said on Twitter that the website is The link for this article located at Mybroadband ZA is no longer available. . The Guardian Mail experiences downtime as Russian cybercriminals target their servers, resulting in widespread inaccessibility for numerous users.. Mail & Guardian Attack, Russian Hacker Incident, Website Cybersecurity. . LinuxSecurity.com Team
Think this guy's a democrat? A former college student has been charged with using the school's computer network to control a botnet and launch distributed denial-of-service (DDoS) attacks against conservative websites belonging to Bill O'Reilly, Ann Coulter and Rudy Giuliani. . Mitchell Frost, 22, of Bellevue, Ohio was charged Friday with one count each of damaging a protected computer system and possessing unauthorized access devices, according to the U. S. attorney's office for the Northern District of Ohio. While enrolled as an undergrad at the University of Akron in Ohio, Frost used the school's computer network to establish a botnet of compromised computers across the United States and other countries, prosecutors said. According to an indictment, Frost scanned the internet searching for vulnerable computer networks to access and gain control over. Frost then used the botnet to initiate DDoS attacks that temporarily interrupted the operation of www.billoreilly.com, and , prosecutors said. The DDoS attacks caused each website to be knocked offline, resulting in damages exceeding $5,000. The link for this article located at SC Magazine is no longer available. . Mitchell Frost, 22, charged for orchestrating DDoS attacks using a school botnet targeting conservative websites.. DDoS Attacks, Botnet Security, Cyber Crime, Website Protection. . LinuxSecurity.com Team
Three Web sites belonging to the U.S. Department of the Treasury have been hacked to attack visitors with malicious software, security vendor AVG says.. AVG researcher Roger Thompson discovered the issue Monday on three Web domains associated with the home page of the U.S. Bureau of Engraving and Printing. As of late Monday, all three Web sites were still actively serving malicious software and the Bureau of Engraving and Printing Web site should be avoided until it's clear that they've been cleaned up, Thompson said in an interview via instant message. Although the Treasury Department could not be reached for comment, IT staff there appear to be aware of the problem. On Tuesday morning, all three sites had apparently been taken offline and were returning a "page not found" error. The link for this article located at Network World is no longer available. . AVG researcher Roger Thompson discovered the issue Monday on three Web domains associated with the h. three, sites, belonging, department, treasury, hacked, attack, visitors. . Alex
Turkish hackers have attacked several Armenian websites ahead of annual commemorative remembrances of the Armenian Genocide. On April 12th, more than 250 sites were impacted when cyber terrorists attacked a server hosting sites including https://armeniasearch.com/ according to the owner of the sites (who wishes to remain anonymous), ANCA Communications Director Elizabeth Chouljian told PanARMENIAN.Net. . The attackers also took down , which is the website for Armenian Directory Yellow pages. Attackers attempted to hack into a second server which hosts https://www.armgate.com but were unsuccessful. The most recent attack is the latest in a series of incidents believed to be related to the approach of April 24, which marks the commemoration of the Armenian Genocide of 1915 and the deaths of more than 1.5 million Armenians at the hands of the Ottoman Turkish authorities. Last month the Armenia National Olympic Committee The link for this article located at PanARMENIAN.Net is no longer available. . The attackers also took down , which is the website for Armenian Directory Yellow pages. Attackers a. turkish, hackers, attacked, armenian, websites, ahead, annual, commemorative, remembrances. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.