The Breach News

Serious Security Vulnerability Discovered in Widely Used LayerSlider WordPress Plugin

A significant security vulnerability has been identified in the LayerSlider plugin for WordPress, posing a serious risk of unauthorized data exposure. This flaw, known as CVE-2024-2879, has been assigned a critical CVSS score of 9.8, indicating its severity. The vulnerability allows unauthenticated attackers to leverage SQL injection techniques to potentially…

Read MoreSerious Security Vulnerability Discovered in Widely Used LayerSlider WordPress Plugin

Hackers Leverage LiteSpeed Cache Vulnerability to Take Full Control of WordPress Sites

A vulnerability classified as high-severity has been discovered in the LiteSpeed Cache plugin for WordPress, which is currently being exploited by cybercriminals to forge unauthorized administrator accounts on affected websites. This alert originated from WPScan, which detailed that the flaw, identified as CVE-2023-40000 with a CVSS score of 8.3, is…

Read MoreHackers Leverage LiteSpeed Cache Vulnerability to Take Full Control of WordPress Sites

FBI Cautions of $40M Cryptocurrency Heist Linked to North Korean Affiliates

The FBI has issued a warning that North Korean cyber actors may seek to liquidate more than $40 million in stolen cryptocurrency. This announcement surfaced on Tuesday amid ongoing investigations into recent blockchain activities linked to a group identified by U.S. authorities as TraderTraitor, also known colloquially as Jade Sleet.…

Read MoreFBI Cautions of $40M Cryptocurrency Heist Linked to North Korean Affiliates

New “Whiffy Recon” Malware Tracks Infected Devices’ Locations via Wi-Fi Every Minute

A new variant of malware known as Whiffy Recon is being deployed via the SmokeLoader loader malware on compromised Windows systems. This new strain’s primary function is to conduct geolocation scans every minute by triangulating the infected device’s position through nearby Wi-Fi access points, utilizing Google’s geolocation API for accuracy.…

Read MoreNew “Whiffy Recon” Malware Tracks Infected Devices’ Locations via Wi-Fi Every Minute

Androxgh0st Botnet Merges with Mozi, Intensifies Assaults on IoT Weaknesses

CloudSEK has indicated that the Androxgh0st botnet has undergone significant evolution, integrating with the notorious Mozi botnet to exploit a multitude of vulnerabilities across web applications and Internet of Things (IoT) devices. This development underscores a broader trend in cyber threats, prompting an urgent need for organizations to understand the…

Read MoreAndroxgh0st Botnet Merges with Mozi, Intensifies Assaults on IoT Weaknesses