Skip to main content

Reuters blog platform may still be out of date despite hack

posted onAugust 8, 2012
by l33tdawg

News service Reuters appears to still be running the same outdated version of WordPress that allowed its blogging platform to be compromised by attackers last week.

Attackers published fake blog posts on Friday, including a purported interview with the leader of the Free Syrian Army. Mark Jaquith, one of the lead developers behind WordPress, told The Wall Street Journal that  Reuters had been running version 3.1.1 instead of the latest version, 3.4.1. There are at least 20 reported vulnerabilities in version 3.1.1.

While blogs.reuters.com was taken offline shortly after the attack, the site is again operational. But it may be still running a vulnerable version. Following a tweet Tuesday by security blogger Brian Krebs, SCMagazine.com analyzed the HTML source code on the Reuters blog site and found a line in the header section indicating the page was generated using WordPress version 3.1.1.

Source

Tags

Reuters Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th