Massive attack on WordPress sites

Kevin Lancaster

MyBroadband Editor
Joined
Apr 4, 2014
Messages
13,564
Reaction score
136
Massive attack on WordPress sites

Attacks on WordPress sites which contain the REST API flaw have increased significantly, with 1.5 million pages defaced.

The WordPress REST API vulnerability allows a remote attacker to craft an HTTP request that pings a REST API endpoint and alters titles and content on the user’s website.
 
My WP site is set to auto update but it didn't install 4.7.2 yet. Weird.
 
Yeah this exploit is going to be a big one! :(

Our systems have already started patching all our customers and reseller's customers wordpress sites for this exploit, without them having to upgrade to 4.7.2 right now.
 
The baddies are going to deface it to say " Scat Blog " !!!

Run like the wind brutha!
 
The cats are safe!

I still some input on the what the heck to do with the landing page. I don't like it, but I cannot think of anything else to do there.
 
Every time I see the thread title I think of,
[video=youtube;u7K72X4eo_s]https://www.youtube.com/watch?v=u7K72X4eo_s[/video]
 
Top
Sign up to the MyBroadband newsletter
X