Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. This whole thing is more than a little bit concerning.

This whole thing is more than a little bit concerning.

Scheduled Pinned Locked Moved Uncategorized
11 Posts 10 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • britt@mstdn.gamesB britt@mstdn.games

    This whole thing is more than a little bit concerning.

    Sharing for any of my friends who use Wordpress and its plugin marketplace.

    Link Preview Image
    Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

    Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

    favicon

    Anchor Hosting (anchor.host)

    jonathankoren@sfba.socialJ This user is from outside of this forum
    jonathankoren@sfba.socialJ This user is from outside of this forum
    jonathankoren@sfba.social
    wrote last edited by
    #2

    @britt “And here is the wildest part. It resolved its C2 domain through an Ethereum smart contract, querying public blockchain RPC endpoints. Traditional domain takedowns would not work because the attacker could update the smart contract to point to a new domain at any time.”

    Clever

    1 Reply Last reply
    0
    • britt@mstdn.gamesB britt@mstdn.games

      This whole thing is more than a little bit concerning.

      Sharing for any of my friends who use Wordpress and its plugin marketplace.

      Link Preview Image
      Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

      Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

      favicon

      Anchor Hosting (anchor.host)

      alison@beige.partyA This user is from outside of this forum
      alison@beige.partyA This user is from outside of this forum
      alison@beige.party
      wrote last edited by
      #3

      @britt Thanks for the heads up. I don't use WP but know lots of people that do.

      1 Reply Last reply
      0
      • britt@mstdn.gamesB britt@mstdn.games

        This whole thing is more than a little bit concerning.

        Sharing for any of my friends who use Wordpress and its plugin marketplace.

        Link Preview Image
        Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

        Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

        favicon

        Anchor Hosting (anchor.host)

        kielkontrovers@norden.socialK This user is from outside of this forum
        kielkontrovers@norden.socialK This user is from outside of this forum
        kielkontrovers@norden.social
        wrote last edited by
        #4

        @britt I always hated those commercial 3rd party plugins. I never trusted them. This was one reason to switch from Wordpress to Hugo.

        1 Reply Last reply
        0
        • britt@mstdn.gamesB britt@mstdn.games

          This whole thing is more than a little bit concerning.

          Sharing for any of my friends who use Wordpress and its plugin marketplace.

          Link Preview Image
          Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

          Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

          favicon

          Anchor Hosting (anchor.host)

          stepschwarz@mastodon.socialS This user is from outside of this forum
          stepschwarz@mastodon.socialS This user is from outside of this forum
          stepschwarz@mastodon.social
          wrote last edited by
          #5

          @britt I'm really surprised this isn't being talked about more. We saw an alert in WP Admin last week and quickly patched our sites, but this is the first mention I've seen of this in the wild.

          1 Reply Last reply
          0
          • britt@mstdn.gamesB britt@mstdn.games

            This whole thing is more than a little bit concerning.

            Sharing for any of my friends who use Wordpress and its plugin marketplace.

            Link Preview Image
            Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

            Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

            favicon

            Anchor Hosting (anchor.host)

            cb@boop.bleepbop.spaceC This user is from outside of this forum
            cb@boop.bleepbop.spaceC This user is from outside of this forum
            cb@boop.bleepbop.space
            wrote last edited by
            #6

            @britt holy moly

            1 Reply Last reply
            0
            • britt@mstdn.gamesB britt@mstdn.games

              This whole thing is more than a little bit concerning.

              Sharing for any of my friends who use Wordpress and its plugin marketplace.

              Link Preview Image
              Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

              Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

              favicon

              Anchor Hosting (anchor.host)

              kgourlay@tech.lgbtK This user is from outside of this forum
              kgourlay@tech.lgbtK This user is from outside of this forum
              kgourlay@tech.lgbt
              wrote last edited by
              #7

              @britt I probably shouldn't be surprised that the market for fraud is so lucrative that buying an entire company to turn it into an engine for backdooring websites is a potentially profitable move.

              1 Reply Last reply
              0
              • britt@mstdn.gamesB britt@mstdn.games

                This whole thing is more than a little bit concerning.

                Sharing for any of my friends who use Wordpress and its plugin marketplace.

                Link Preview Image
                Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

                Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

                favicon

                Anchor Hosting (anchor.host)

                perlman@indieweb.socialP This user is from outside of this forum
                perlman@indieweb.socialP This user is from outside of this forum
                perlman@indieweb.social
                wrote last edited by
                #8

                @britt I stopped using WordPress this year because of how many people try to hack it everyday.

                1 Reply Last reply
                0
                • R relay@relay.mycrowd.ca shared this topic
                  em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                • britt@mstdn.gamesB britt@mstdn.games

                  This whole thing is more than a little bit concerning.

                  Sharing for any of my friends who use Wordpress and its plugin marketplace.

                  Link Preview Image
                  Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

                  Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

                  favicon

                  Anchor Hosting (anchor.host)

                  numerfolt@kirche.socialN This user is from outside of this forum
                  numerfolt@kirche.socialN This user is from outside of this forum
                  numerfolt@kirche.social
                  wrote last edited by
                  #9

                  @britt Thank you 🙂

                  1 Reply Last reply
                  0
                  • britt@mstdn.gamesB britt@mstdn.games

                    This whole thing is more than a little bit concerning.

                    Sharing for any of my friends who use Wordpress and its plugin marketplace.

                    Link Preview Image
                    Someone Bought 30 WordPress Plugins and Planted a Backdoor in All of Them.

                    Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into

                    favicon

                    Anchor Hosting (anchor.host)

                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.io
                    wrote last edited by
                    #10

                    @britt From the perspective of capitalist walled-garden plugin repositories, this is everything working as intended.

                    You're *supposed* to be able to monetize people's trust in you by selling that to malicious parties, duh.

                    🤬

                    dalias@hachyderm.ioD 1 Reply Last reply
                    0
                    • dalias@hachyderm.ioD dalias@hachyderm.io

                      @britt From the perspective of capitalist walled-garden plugin repositories, this is everything working as intended.

                      You're *supposed* to be able to monetize people's trust in you by selling that to malicious parties, duh.

                      🤬

                      dalias@hachyderm.ioD This user is from outside of this forum
                      dalias@hachyderm.ioD This user is from outside of this forum
                      dalias@hachyderm.io
                      wrote last edited by
                      #11

                      @britt There are so many things they could do to make this kind of operation less lucrative, less effective, more risky, etc. and it's very telling that they won't.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups