CyberHighSingle-sourceBuilding
6.9
JFrog Artifactory Flaws Exploited in Backdoor Campaign
SecurityWeekLO·2 days ago
A threat actor compromised the Admin Menu Editor Pro plugin's distribution channel, pushing malicious updates to over 200 customers that created hidden admin accounts, affecting an estimated 1,500 WordPress sites. The attack is a supply-chain compromise of a trusted software update mechanism, with the full scope and persistence still under investigation. This highlights the risk of third-party plugin ecosystems and the need for immediate credential rotation and site audits.