WordPress-ийн эмзэг байдлыг ашиглан хакерууд вэбсайтуудыг эзлэн авч байна

Published:

Энэхүү мэдээ, нийтлэлийг хиймэл оюун боловсруулав.

WordPress программ хангамжийн аюулгүй байдлын ноцтой сул талууд илэрсэнтэй холбогдуулан хакерууд хамгаалалтгүй вэбсайтуудад халдах тохиолдол нэмэгджээ.

Кибер аюулгүй байдлын Patchstack, Hexastrike, болон WatchTowr компаниудын мэдээлснээр, WordPress-ийн 6.9.0-6.9.4 болон 7.0.0-7.0.1 хувилбаруудад илэрсэн хоёр чухал сул талыг хакерууд идэвхтэй ашиглаж байна. Даваа гарагийн байдлаар сая сая вэбсайт эрсдэлд өртөөд байгаа бөгөөд аюулгүй байдлын мэргэжилтнүүд хэрэглэгчдийг программ хангамжаа нэн даруй шинэчлэхийг уриалж байна.

Searchlight Cyber-ийн судлаач Адам Кюс-ийн илрүүлсэн “WP2Shell” хэмээх энэхүү сул тал нь хакеруудад вэбсайтыг бүрэн хяналтдаа авах боломжийг олгодог. WordPress-ийн албан ёсны статистик мэдээллээр 400 гаруй сая вэбсайт эдгээр хувилбарыг ашиглаж байж болзошгүй байгаа ч кибер аюулгүй байдлын зөвлөх Даниел Кард-ын хийсэн судалгаагаар нийт вэбсайтуудын 15 хүрэхгүй хувь нь халдлагад өртөх эрсдэлтэй байна.

Эрсдэлийг бууруулахын тулд WordPress албадан шинэчлэлт хийх арга хэмжээг авчээ. Үүний зэрэгцээ Cloudflare зэрэг үйлчилгээнүүд халдлагыг блоклох, вэб галт хана ашиглах зэрэг хамгаалалтын арга хэмжээнүүд нь хохирлын хүрээг хязгаарлахад тус дэм болж байна. Automattic болон WordPress.org энэ асуудлаар одоогоор албан ёсны тайлбар өгөөгүй байна.

Дэлгэрэнгүйг эх сурвалжаас харах

↓Эх сурвалжийг нээх ↓

Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.

Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.

It’s unclear how many WordPress-powered websites on the internet are at risk, but it’s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don’t reflect websites that have recently been patched.

Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 4,200 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million.

The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked.

Automattic, as well as WordPress.org, the project that develops WordPress’ open-source code, did not immediately respond to a request for comment.

One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

- Зар сурталчилгаа -

Та юу гэж бодож байна?

Сэтгэгдлээ оруулна уу!
Please enter your name here

MFC.mn сайтад сэтгэгдэл оруулахад анхаарах зүйлс

Холбоотой

spot_img

Шинэ

spot_img