A cybersecurity firm has reported that hackers are actively hijacking over 10,000 WordPress sites to distribute malware targeting both Windows and macOS users. The ongoing campaign, described as 'spray and pray,' involves the use of fake browser update pages to spread malicious software. As of January 30, 2025, the attack remains live, affecting thousands of websites. The firm monitoring the situation, csideai, emphasizes the exploitation of outdated WordPress sites as a primary vector for this attack. The scale of the breach highlights significant vulnerabilities within the WordPress ecosystem.
Hackers are exploiting outdated WordPress sites to spread password-stealing malware to Windows & Mac users. The attack is still live, affecting thousands of websites. Read more in @lorenzofb's @TechCrunch story featuring research from our portfolio company @csideai 👇…
✈️💻Air Europa avisa a sus clientes de que los 'hackers' podrían estar «cometiendo actividades delictivas» con sus datos, tras el ciberataque del año pasado ✍️Por @tonierres https://t.co/8laDyHXXBR
Alerta de ciberseguridad: más de 10.000 sitios WordPress distribuyen malware en Windows y macOS https://t.co/XWQDl5jfXV