How to secure your content management system

Popular content management systems are easy to install and use. But how easy is it to keep them secure?
Categories:

Security world
Technology

Tags: CMSCMS securitycontent management systemsdrupalJoomlawordpress

(Read more…)

The post … Continue reading How to secure your content management system

Traffic manipulation and cryptocurrency mining campaign compromised 40,000+ machines

Unknown attackers have compromised 40,000+ servers, networking and IoT devices around the world and are using them to mine Monero and redirect traffic to websites hosting tech support scams, malicious browser extensions, and so on. The campaign, dubbed… Continue reading Traffic manipulation and cryptocurrency mining campaign compromised 40,000+ machines

8 Tips to Harden Your Joomla Installation

Joomla arrived on the scene in 2005 as a fork of the Mambo content management system (CMS). Downloaded over 91 million times, it has since eclipsed Mambo to become a ubiquitous platform for websites of all sizes. According to last year’s Hacked W… Continue reading 8 Tips to Harden Your Joomla Installation

Thousands of WP, Joomla and SquareSpace sites serving malicious updates

Thousands of compromised WordPress, Joomla and SquareSpace-based sites are actively pushing malware disguised as Firefox, Chrome and Flash Player updates onto visitors. This campaign has been going on since at least December 2017 and has been gaining s… Continue reading Thousands of WP, Joomla and SquareSpace sites serving malicious updates

Thousands of compromised websites spreading malware via fake updates

Malicious hackers have been exploiting thousands of legitimate websites since at least December 2017 in a sophisticated campaign that has disguised malware as fake software updates.
Read more in my article on the Tripwire State of Security blog.
Continue reading Thousands of compromised websites spreading malware via fake updates

‘FakeUpdates’ campaign leverages multiple website platforms

Browser update? Do not trust, and do verify before downloading potential malware.
Categories:

Social engineering
Threat analysis

Tags: chromeChtonicfake updatesFakeUpdatesfirefoxflashJoomlamalvertisingmalwareratSquarespacewordpress

(Read mor… Continue reading ‘FakeUpdates’ campaign leverages multiple website platforms

Drupal Forewarns ‘Highly Critical’ Bug to be Patched Next Week

Drupal is giving developers ample time to prepare for an update that patches a “highly critical” flaw because exploits might be developed within hours or days of disclosure. Continue reading Drupal Forewarns ‘Highly Critical’ Bug to be Patched Next Week