My guess: crowdstrike almost certainly tested what was *supposed* to be in that update but their distribution pipeline failed to retrieve the actual update before pushing it out and sent out an empty file, a situation they did *not* test for
🚨Alert to all WordPress users! Beware of the latest phishing scam using fake CVE-2023-45124. This scheme lures users into installing a backdoor plugin. #WordPress#WP#CyberSecurity https://t.co/OTrF064RRD
Earn up to $10,000 for finding Vulnerabilities in WordPress Software. For the next 20 days, we have added a 6.25X multiplier to all bug bounties, starting NOW. These are some of the highest payouts for finding vulnerabilities in the history of WordPress. If you're a vulnerability researcher, this is your moment! https://t.co/5wckqkqUoP
High altitude mountaineer Ed Viesturs joined the Wordfence team over the weekend in Banff, Canada to elevate our thinking. An amazing guy with an incredible list of accomplishments. Inspirational!! Thanks Ed!!
https://t.co/8jiMSxO8bk
@davevsdave@wpcerber@wordfence We do our best to keep our vulndb records up to date - something that takes a tremendous amount of human expertise and labor even with automation. Still, errors occur which is why we encourage feedback.
@davevsdave@wpcerber@wordfence Updated-FWIW wp-cerber has been suspended from the repository since before the patch for this issue (9.3.2 isn't available on the repo) and we can't practically monitor every vendor's individual website. The Vulndb entry does have a feedback email address for situations like this
It's been mentioned that the ssh key we're seeing is the one in the @horizon3ai deep dive. Unclear if it's theirs or the same one they're seeing. Could be naive attackers copying their payload verbatim. If it is horizon3 sending out requests I'm assuming they got permission first
@GossiTheDog We saw nearly 2 dozen ips by end of day and we only started looking this morning. Only a couple requests each from most of them but a few are a bit more active
1/ This morning, the Wordfence Threat Intelligence team began tracking exploit attempts targeting CVE-2022-40684 on our network of over 4 million protected websites.
@happysmash27@GorillaGlue Hi! We don’t actually block tor outright. We do block IP address that have recently been used to attack Wordpress sites, and don’t make any special exceptions for tor. You can probably use a different tor exit node that hasn’t recently been used to attack a bunch of websites
I didn’t want to post yesterday in anger. I don’t post much on main. But yeah I’m still angry and sad, and also scared because the vector they chose was eliminating the right to privacy. maybe I don’t personally have to worry if I keep my head down, but people I care about do
@vikasprogrammer@Bovelett@wordfence Also I think some of our readers enjoy finding out what botnets are up to and what sort of payloads they're dropping
@vikasprogrammer@Bovelett@wordfence We did clarify that only a few thousand sites were still likely vulnerable, but quantity has a quality all its own, and without a google dork, a bot scan against a couple million sites is more likely to hit the few thousand remaining vulnerable installations than a smaller attack
@vikasprogrammer@Bovelett@wordfence Hi Vikas, we do actually have attack data from before last week, but it was a few hundred attacks a day at most. We feel there's a genuine difference in scale between "a few hundred" and "millions" that puts remaining unpatched sites at higher risk and makes the story newsworthy.
A bunch of my @wordfence instructor videos just went live! Check 'em out :D
https://t.co/tNO0scnOqh
https://t.co/HVTziTo9vO
https://t.co/lmy9i6bN4U
https://t.co/Xqtw78x3nX
https://t.co/RtNjtrbiTI
https://t.co/DE7RFteWIg