Trend Micro sees mass compromise of WordPress sites serving client-side exploits
Trend Micro researchers are reporting that a mass compromise of WordPress sites is currently on going with attacked sites serving client-side exploits and malware in the hopes of luring users to click on the malicious links, ultimately resulting in the installation of the Blackhole Exploit kit that targets vulnerabilities cited in CVE-2010-0188 and CVE-2010-1885.
The researchers say cybercriminals are impersonating the Better Business Bureau and LinkedIn in their spamvertised emails, enticing end and corporate users into clicking on the malicious links found in the emails.