Follow the latest coverage, related explainers and connected technology stories.
Attackers are exploiting stored XSS vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to plant backdoors and create hidden administrator accounts. Users are advised to update to Ninja Forms version 3.15.4 or later and WPC Product Bundles version 8.6.7 or later, while scanning sites that may have already been compromised.
Unknown attackers seized Microsoft’s official X account, followed by more than 13 million people, and posted content promoting a cryptocurrency token in a suspected pump-and-dump scheme. Microsoft confirmed the hack, deleted the posts, and launched an investigation, while denying any connection to the token.
The domain third-party.com, used for years as a default address in programming documentation and code examples, has begun displaying a fake Cloudflare page that pressures Windows users into executing malicious PowerShell commands. There are no confirmed reports that the attack succeeded, but the domain’s prevalence in public repositories and projects makes it a potential danger for code copied verbatim.