It is our recommendation that site owners using Total Donations delete–not just deactivate–the vulnerable plugin as soon as possible to secure their sites. The following article details the issues present in Total Donations, as well as the active attacks against the plugin. We’ll also take a look at our disclosure process, and the steps we took in our attempts to contact the plugin’s developers to reach a resolution.
The US Department of Homeland Security (DHS) has issued an emergency directive tightening DNS security after a recent wave of domain hijacking attacks targeting government websites. Make sure the government site you are on is really the government, and not an impostor site.
AA19-024A: DNS Infrastructure Hijacking Campaign 01/24/2019 03:01 PM EST
CISA Emergency Directive on DNS Infrastructure Tampering 01/22/2019 06:48 PM EST
CISA Releases Blog on Emergency Directive 01/24/2019 06:38 PM EST
Emotet is moving, shape-shifting target for admins and their security software. Here’s what we’ve learned from dealing with outbreaks.
A hacked Nest camera broadcast the fake warning about incoming North Korean missiles, sending a family into “five minutes of sheer terror.”