How a URL shortener allows malicious actors to hijack visitors’ CPU power

URL shorteners are often used by malware peddlers and attackers to trick users into following a link they otherwise wouldn’t. But Coinhive’s URL shortener carries an added danger: your CPU power can be surreptitiously hijacked to mine Moner… Continue reading How a URL shortener allows malicious actors to hijack visitors’ CPU power

Million-Plus WordPress Sites Exposed by Vulnerable Plugin

The popular NextGEN Gallery WordPress plugin was recently patched to address a “severe” SQL injection vulnerability that put website databases at risk. Continue reading Million-Plus WordPress Sites Exposed by Vulnerable Plugin

1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure

WordPress security experts said that 1.5M sites have been defaced following the disclosure of a silently fixed content injection vulnerability. Continue reading 1.5M Unpatched WordPress Sites Hacked Following Vulnerability Disclosure

Toolsmith – GSE Edition: Image Steganography & StegExpose

Cross-posted on the Internet Storm Center Diary.Updated with contest winners 14 DEC. Congrats to: Chrissy @SecAssistanceOwen Yang @HomingFromWorkPaul Craddy @pcraddyMason Pokladnik – Fellow STI gradElliot Harbin @klax0ffIn the last of a three part (Pa… Continue reading Toolsmith – GSE Edition: Image Steganography & StegExpose