🖱️ One Click to Own Your Site + The Job Interview That Drained $10.7M
Two stories from today's security headlines share an uncomfortable theme: the attack didn't break through your defenses — it got someone on the inside to open the door. One took a single click from a website administrator. The other took a job interview.
The WordPress Flaw That Only Needs One Admin Click
Researchers disclosed a WordPress vulnerability nicknamed "Click2Shell" that lets an attacker take over a website by tricking a logged-in administrator into clicking a single link. The trick works because WordPress's admin panel didn't properly sanitize a piece of text called a theme slug — which meant an attacker could quietly use the administrator's own active login session to install a theme of their choosing.
When that's chained with a separate bug in the "Mobile Repair Zone" theme, it escalates all the way to full remote code execution — meaning the attacker can run whatever commands they want on the server. Critically, the attacker never needs a WordPress account of their own. They just need an admin to click once.
Here's the "so what": WordPress runs a huge share of the internet's small business sites, blogs, and online stores. If you run one, your site's administrator is now a single misdirected click away from handing over the whole thing. Patch to WordPress 7.1.1 (or the backported 7.0.5, 6.9.8, and 6.8.9) today, and consider setting DISALLOW_FILE_MODS, which blocks the theme-installation step entirely. No CVE had been assigned at the time of disclosure — so don't wait for one.
North Korea's Fake Job Interviews Hit 30,000 Devices and $10.7M
A joint advisory from the US, Japan, Australia, and Germany has attributed a sprawling campaign to a North Korean group tracked as WaterPlum (also known as "Contagious Interview"). Between December 2025 and July 2026, the group compromised more than 30,000 devices across over 100 countries and drained $10.7 million from more than 7,000 cryptocurrency wallets.
The delivery method is the part worth internalizing: fake technical job interviews posted on legitimate recruiting platforms. Candidates were walked through what looked like a normal coding assessment and ended up installing malware — five different families of it, with names like BeaverTail and InvisibleFerret. The theft didn't stop at money. North Korean IT operatives later reused identity documents stolen from those victims to fraudulently land real jobs at Western companies.
The "so what" cuts two ways. If you're job hunting, treat any "take-home assessment" that asks you to run unfamiliar code on your personal machine as a serious red flag. And if you're hiring, this is a reminder that the résumé and ID in front of you may belong to someone else entirely — identity verification in your hiring pipeline is now a security control, not just an HR formality.
The Bottom Line
Patch your WordPress install, and teach your team that the most dangerous attachment isn't always in an email — sometimes it's in a job offer.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment