Arbitrary File Upload Vulnerability in WordPress Plugin Let Attackers Hack 30,000 Website
ID: 2e46b68a-6bb0-5a5a-a0f7-9d65c2c89cf9
STIX ID: report--2e46b68a-6bb0-5a5a-a0f7-9d65c2c89cf9
Feed Name: GBHackers
**BadPilot (Seashell Blizzard / Sandworm)** — A Russian state-sponsored subgroup has run a multi-year campaign (active since at least 2021) targeting critical infrastructure worldwide by exploiting multiple internet-facing vulnerabilities (including CVE-2024-1709 and CVE-2023-48788) to gain persistent access, harvest credentials, modify DNS and inject malicious JavaScript, and deploy remote management tools; the subgroup has supported destructive operations in Ukraine and expanded operations to North America, Europe, and APAC, underscoring high-risk, nation-state cyber activity and the need for prompt patching and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
