Hackers are compromising WordPress 3.2.1 blogs in order to infect their visitors with the notorious TDSS rootkit, according to researchers from Web security firm Websense.
It's not clear how the websites are being compromised, but there are publicly known exploits for vulnerabilities that affect WordPress 3.2.1, which is an older version of the popular blog publishing platform.
Researchers have discovered a spike in malware infecting thousands of WordPress websites that use a popular image tool.
The attacks came to light after French media outlet, The Poitou-Charentes Journal, began hosting on malicious code on its WordPress site. Avast senior researcher Jan Sirmer found attackers had exploited weak FTP server authentication credentials and a vulnerability in the TimThumb image resizer to upload malicious PHP files to the site.
Recent comments