FBI Warns Of Islamic State Campaign Against WordPress Sites

The FBI has warned of an ongoing cyber campaign by individuals sympathetic to the Islamic State in the Levant (ISIL), targeting a range of different websites, using known vulnerabilities in WordPress.

The bureau warned that the defacements have affected Website operations and the communication platforms of news organisations, commercial entities, religious institutions, federal/state/local governments, foreign governments, and a variety of other domestic and international Websites.

WordPress Hacks.

FBIThe FBI did state that the defacements demonstrate low-level hacking skills, but said that they are disruptive and often costly to repair and fix. It said the attackers are not actual members of ISIL, but are using the ISIL name to gain more notoriety than the underlying attack would have otherwise gathered.

It seems that the hackers are exploiting WordPress CMS plug-in vulnerabilities. These flaws can allow attackers to take control of an affected system, gain unauthorised access, bypass security restrictions, inject scripts, and steal cookies from computer systems or network servers.

“An attacker could install malicious software; manipulate data; or create new accounts with full user privileges for future Web site exploitation,” warned the bureau.

The FBI urged firms to apply the available software patches to plug these identified vulnerabilities. Meanwhile it seems that the ISIL defacement of WordPress websites is not the only problem at the moment.

Fraudulent Websites

The FBI also issued an alert for an unrelated matter, warning that criminals are hosting fraudulent government Websites in a effort to collect personal and financial information from unwitting Web users.

“Victims use a search engine to search for government services such as obtaining an Employer Identification Number (EIN) or replacement social security card,” said the FBI. “The fraudulent criminal websites are the first to appear in search results, prompting the victims to click on the fraudulent government services website.”

Earlier this year, social media accounts linked to the US military suffered a cybersecurity attack from hackers claiming to support the terrorist Islamic State militant group.

The @CENTCOM Twitter account, representing the US command that oversees operations in the Middle East, was hacked and defaced with messages praising Islamic State.

US President Barack Obama recently created a new sanctions scheme after he signed an executive order that classified malicious cyber attacks as a “national emergency”.

This means that the US Treasury now has the power to freeze assets and bar other financial transactions of entities engaged in cyber attacks. Hackers who conduct commercial espionage in cyberspace can now be listed on the official sanctions list of specially designated nationals.

Are you a security pro? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

France Fines Apple Over Ad Tracking Feature

Apple fined 150m euros over App Tracking Transparency feature that it says abuses Apple's market…

9 hours ago

OpenAI To Release Open-Weight AI Model

OpenAI to release customisable open-weight model in coming months as it faces pressure from open-source…

9 hours ago

Samsung AI Fridge Creates Shopping Lists, Adjusts AC

Samsung's Bespoke AI-powered fridge monitors food to create shopping lists, displays TikTok videos, locates misplaced…

10 hours ago

Huawei Consumer Revenues Surge Amidst Smartphone Comeback

Huawei sees 38 percent jump in consumer revenues as its smartphone comeback continues to gather…

10 hours ago

China Approves First ‘Flying Car’ Licences

In world-first, China approves commercial flights for EHang autonomous passenger drone, paving way for imminent…

11 hours ago

Microsoft Shutters Shanghai Lab In Latest China Pullback

Microsoft closes down IoT and AI lab it operated in Shanghai tech district in latest…

11 hours ago