A previously unknown Linux malware has been exploiting 30 vulnerabilities in multiple outdated WordPress plugins and themes to inject malicious JavaScript. . According to a report by antivirus vendor Dr. Web , the malware targets both 32-bit and 64-bit Linux systems, giving its operator remote command capabilities. The main functionality of the trojan is to hack WordPress sites using a set of hardcoded exploits that are run successively, until one of them works. . Security firm Kaspersky has identified malicious code targeting both 32-bit and 64-bit versions of Linux OS, exploiting vulnerabilities in legacy themes and plugins from Joomla.. Linux Malware, WordPress Exploits, Plugin Security. . LinuxSecurity.com Team
The EU General Protection Data Regulation (GDPR) is supposed to make companies take extra care with their customers’ personal data. That includes gathering explicit consent to use information and keeping it safe from identity thieves. . WP GDPR Compliance is a plugin that allows WordPress website owners to add a checkbox to their websites. The checkbox allows visitors handing over their data to grant permission for the site owners to use it for a defined purpose, such as handling a customer order. It also allows visitors to request copies of the data that the website holds about them. The link for this article located at Naked Security/Sophos is no longer available. . Learn about the security breach affecting a widely-used WordPress GDPR compliance plugin, resulting in unauthorized access to sensitive user data and heightened risks for site admins. WordPress GDPR Compliance, Data Protection, Identity Theft, Cyber Security, GDPR Regulation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.