Off-Brand Android Devices Come Infected With a Trojan A botnet infected more than 1 million off-brand Android devices manufactured in China, which reached consumers with a backdoor already installed. Scammers used the devices for programmatic ad fraud, click fraud and converting the devices into a residential proxy.
Over 1,000 websites powered by WordPress have been infected with a third-party JavaScript code that injects four separate backdoors.
"Creating four backdoors facilitates the attackers having multiple points of re-entry should one be detected and removed," c/side researcher Himanshu Anand said in a Wednesday analysis.
The malicious JavaScript code has been found to be served via cdn.csyndication[
A vulnerability was found in ninjateam Notibar Plugin up to 2.1.5 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-1672. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability was found in LinZhaoguan pb-cms 1.0.0 and classified as critical. This issue affects some unknown processing of the file /admin#themes of the component Add New Topic Handler. The manipulation of the argument Topic Key leads to deserialization.
The identification of this vulnerability is CVE-2025-2043. The attack may be initiated remotely. Furthermore, there is an exploit available.