Unmaintained WordPress Plugin Used to Compromise Website

Attackers are using the abandoned WordPress plugin, Eval PHP, to compromised websites by injecting stealthy backdoors. Eval PHP is an old legitimate WordPress plugin that allows site admins to embed executable PHP code on their website pages and posts. The plugin has...

5 Steps for Securing Your Software Supply Chain

RSA Conference just published an article that I’ve written on the 5 steps for securing your software supply chain. Most modern applications are assembled from open source components with developers typically writing less than 15% of the code for their...

March 2023 Broke Ransomware Attack Records

March 2023 has been the most prolific month recorded by cybersecurity analysts, with 459 recorded ransomware. This is up 91% from the previous month. According to NCC group, the reason for the record-breaking attack is due to a zero-day vulnerability in Fortra’s...

Australians Scam Losses in 2022 increased by 80%

The Australian Competition & Consumer Commission (ACCC) says Australians lost a record $3.1 billion to scams in 2022. This is an 80% increase over the total losses recorded in 2021. Investment scams accounted for the most losses, at $1.5 billion. This is followed...

Chatting with a Hacker

Four corners from the ABC news just published an article about their conversation with one of the hackers who’s worked for the cyber criminal gangs behind some of Australia’s largest data breaches. When asked whether he see Australia as an attractive...

Google Chrome Security Update for Zero-Day Vulnerability

Google has just released an emergency Chrome security update to address a zero-day vulnerability. The vulnerability is assigned CVE-2023-2033 and is a type confusion weakness in the Chrome JavaScript Engine. It affects the Chrome browser on Windows, Mac and Linux. The...