FBI issues WordPress warning regarding ISIS sympathizers

There’s one more a reason that the FBI sent its representative to NamesCon 2015, aside from participating in the stolen domains debate.

The Federal Bureau of Investigation has been monitoring the amount and type of web site defacements, performed by ISIS sympathizers.

In particular, it seems that a lot of this type of hacking activity takes advantage of WordPress exploits, that might exist in plug ins or other WordPress add-ons.

fbi-psa

The FBI issued an announcement, that attempts to explain the issue:

“Researchers continue to identify WordPress Content Management System (CMS) plug-in vulnerabilities, which could allow malicious actors to take control of an affected system. Some of these vulnerabilities were exploited in the recent Web site defacements noted above. Software patches are available for identified vulnerabilities.

Successful exploitation of the vulnerabilities could result in an attacker gaining unauthorized access, bypassing security restrictions, injecting scripts, and stealing cookies from computer systems or network servers. An attacker could install malicious software; manipulate data; or create new accounts with full user privileges for future Web site exploitation.”

Furthermore, the FBI announcement offers advice about managing such cyberthreats against the WordPress platform:

“Methods being utilized by hackers for the defacements indicate that individual Web sites are not being directly targeted by name or business type. All victims of the defacements share common WordPress plug-in vulnerabilities easily exploited by commonly available hacking tools.”

The FBI recommends the following actions be taken:

For the full announcement by the FBI, click here.

 

Copyright © 2024 DomainGang.com · All Rights Reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *

 characters available