Skip to main content

Tag: trojanized updates

2 articles

WordPress website backend interface on a laptop screen in a workspace.

Compromised Plugin Backdoors 1,500 WordPress Sites

A malicious update to the WordPress plugin Admin Menu Editor Pro infected around 1,500 sites with a backdoor, after hackers compromised the plugin's update server and uploaded a trojanized version. The attackers even created a hidden user account and installed a web shell on affected sites.

Analyst 207
Rows of computer servers and equipment in a brightly-lit server room.

Hackers Breach TrueConf Servers to Deploy Backdoors via Trojanized Updates

Hackers have breached TrueConf servers by exploiting a gaping security hole - an open TCP port that lets them in without needing a password, then using trojanized updates to deploy backdoors and take control. This sneaky attack vector has been used by threat actors like Head Mare to spread malware and gain unauthorized access.

Analyst 207