WordPress Users Beware: Google Ads Used for ManageWP Phishing

Date:

Cybersecurity Alert: Phishing Attack Targets ManageWP Users via Google Ads

A recent phishing campaign is exploiting Google Ads to deceive users of ManageWP, a popular platform for managing multiple WordPress sites. Cybercriminals have created a fake login page that appears legitimate, utilizing a method known as adversary-in-the-middle (AitM) to capture user credentials in real-time.

The attack affects web developers, agencies, and enterprises using ManageWP, which manages over 1 million websites. Victims searching for the login page may unknowingly click on a malicious Google search result, leading them to a counterfeit site where their credentials are sent directly to the attackers. Once logged in, victims are prompted to provide a two-factor authentication code, giving attackers full access to their accounts.

To protect yourself, always verify web addresses and enable multi-factor authentication when possible. Be cautious of unusual login prompts.

Risk Level: High

Source: View Original Report

Share post:

spot_imgspot_img

Popular

More like this
Related

WPScan 4.0.0: Critical XSS Vulnerability Exposed!

WordPress Vulnerability Report: WPScan 4.0.0 Released Introduction The latest version of...

119 Edge Extensions: Malware Disguised as Useful Tools

Cybersecurity Alert: Malware Infiltrates Popular Browser Extensions A recent malware...

200K WordPress Sites Face XSS Risk from Burst Statistics Plugin

Critical Vulnerability Discovered in Burst Statistics Plugin for WordPress On...

Foxconn Cyberattack: Nitrogen Ransomware Strikes WordPress Sites

Cyberattack Hits Foxconn: Major Data Breach Reported Foxconn, the largest...