Loading...
Loading...
Browse all stories on DeepNewz
VisitSupply Chain Attack on Polyfill.io and WordPress Plugins Impacts Over 100,000 Websites
Jun 26, 2024, 05:06 AM
A significant supply chain attack has impacted over 100,000 websites using the Polyfill.io service. The attack began after the domain was acquired by the Chinese company 'Funnull,' which injected malicious code into the service. This code redirected visitors to unwanted sites without the website owners' knowledge. The attack has also affected WordPress plugins, with as many as 36,000 sites compromised. Security experts are advising immediate removal of the Polyfill.io code from affected websites to mitigate the risk. The cdn.polyfill.io domain is currently being used in the attack, and experts have called on Namecheap to take action. The attack was reported by darkreading.
View original story
Markets
No • 50%
Yes • 50%
Court records or official announcements
Yes • 50%
No • 50%
Official statement from Namecheap or confirmation from security experts
No • 50%
Yes • 50%
Reports from security firms or official statements from affected parties
Taking legal action against Funnull • 33%
Collaborating with affected parties • 33%
Issuing patches and advisories • 33%
Announcements from cybersecurity firms or reports in cybersecurity news
Polyfill.io service • 33%
Both equally • 33%
Compromised WordPress plugins • 33%
Security firm reports or official investigations
Switching to alternative services • 33%
Removal of Polyfill.io code • 33%
Implementing additional security measures • 33%
Surveys or reports from security experts and affected websites