Patterns, colors, fonts, and more. Our new homepage design tool guides you through making your creative vision a reality.
WORDPRESS
Hackare injicerar kreditkortsstöldare i betalningsbehandlingsmoduler

A new credit card stealing hacking campaign is doing things differently than we have seen in the past by hiding their malicious code inside the ‘Authorize.net’ payment gateway module for WooCommcerce, allowing the breach to evade detection by security scans.
Historically, when threat actors breach a commerce site like Magenta or WordPress running WooCommerce, they inject malicious JavaScript into the HTML of the store or customer checkout pages.
These scripts will then steal inputted customer information on checkout, such as credit card numbers, expiration dates, CVV numbers, addresses, phone numbers, and email addresses.
However, many online merchants now work with security software companies that scan the HTML of public-facing eCommerce sites to find malicious scripts, making it harder for threat actors to stay hidden.
To evade detection, the threat actors are now injecting malicious scripts directly into the site’s payment gateway modules used to process credit card payments on checkout.
As these extensions are usually only called after a user submits their credit card details and checks out at the store, it may be harder to detect by cybersecurity solutions.
The campaign was discovered by website security experts at Sucuri after being called in to investigate an unusual infection on one of their client’s systems.
Targeting payment gateways
WooCommerce is a popular eCommerce platform for WordPress used by roughly 40% of all online stores.
To accept credit cards on the site, stores utilize a payment processing system, such as Authorize.net, a popular processor used by 440,000 merchants worldwide.
On the compromised site, Sucuri discovered that threat actors modified the “class-wc-authorize-net-cim.php” file, one of Authorize.net’s files supporting the payment gateway’s integration to WooCommerce environments.
The code injected at the bottom of the file checks if the HTTP request body contains the “wc-authorize-net-cim-credit-card-account-number” string, which means it carries payment data after a user checks out their cart on the store.
If it does, the code generates a random password, encrypts the victim’s payment details with AES-128-CBC, and stores it in an image file that the attackers later retrieve.

A second injection performed by the attackers is on “wc-authorize-net-cim.min.js,” also an Authorize.net file.
The injected code captures additional payment details from input form elements on the infected website, aiming to intercept the victim’s name, shipping address, phone number, and zip/postal code.
Evading detection
Another notable aspect of this campaign is the stealthiness of the skimmer and its functions, which make it particularly hard to discover and uproot, leading to extended periods of data exfiltration.
First, the malicious code was injected in legitimate payment gateway files, so regular inspections that scan websites’ public HTML or look for suspicious file additions wouldn’t yield any results.
Secondly, saving stolen credit card details on an image file isn’t a new tactic, but strong encryption is a novel element that helps attackers evade detection. In past cases, threat actors stored stolen data in plaintext form, used weak, base64 encoding, or simply transferred the stolen information to the attackers during checkout.
Thirdly, the threat actors abuse WordPress’s Heartbeat API to emulate regular traffic and mix it with the victims’ payment data during exfiltration, which helps them evade detection from security tools monitoring for unauthorized data exfiltration.

As MageCart actors evolve their tactics and increasingly target WooCommerce and WordPress sites, it is essential for website owners and administrators to stay vigilant and enforce robust security measures.
This recent campaign discovered by Sukuri highlights the growing sophistication of credit card skimming attacks and the attackers’ ingenuity in bypassing security.
WORDPRESS
Anpassade temadesigner blev precis enklare – WordPress.com Nyheter

Whether you want a simple blog that highlights recent posts, a visually stunning portfolio, or an online home for your small business, your website should be just as unique as you are. That’s why we’re excited to introduce a new site design tool that guides you through the process of creating a memorable custom homepage.
Our designers have put together a library of hundreds of patterns, colors, and fonts that you can mix and match for whichever distinctive vibe you’re going for.
Try it out today by clicking the button below:
Create your own design
When you create a new site at WordPress.com, you’ll now find the option to start from a Blank Canvas. This is where you become the designer (with a little help from us): We’ll guide you through decisions on layout, colors, fonts, and more. No matter your goals for your site, we have the building blocks to help you turn your creative vision into reality.
Pick the perfect palette
Paint your patterns with the click of a button, applying custom color palettes to your entire page via our global styles feature. Our simple tools allow you to take the artistic lead on your site. Are you Blueberry Sorbet? Midnight Citrus? Perhaps a moody Charcoal? We have dozens of colorful options to set a mood that works for you and your audience.
Find a fitting font
Whether something stately and classic or sleek and modern, the typeface you use sets the tone for everything you’re trying to do with your site. Our thoughtful and engaging one-click font pairings will have you feeling like an expert typographer in no time.
Edit with ease
Patterns? Check. Colors? Check. Fonts? Check. You’ve got the basics of your site set up. Now it’s time to harness the power of the Site Editor. Bring your page to life by adding images, content, products to sell, and more. As you get comfortable, continue to experiment by adding or removing patterns, playing with colors and fonts, and making your site look and feel exactly the way you want it to.
Click below to get started with our DIY site assembler:
Läs mer
Need some extra help? Our new Quick Launch course will guide you through what to include on a compelling homepage, and how to tie it together with our new DIY design assembler. Additionally, here’s a few more resources to get you started with designing on WordPress.com:
Join 99,266,292 other subscribers
WORDPRESS
Hur man filtrerar WooCommerce-produkter (steg-för-steg handledning)

Are you looking for a way to filter products by attribute in your WooCommerce store?Filtering your WooCommerce products by attribute makes it easier …
Källlänk
WORDPRESS
Grattis på 20-årsdagen, WordPress! Vi skulle inte vara här utan dig – WordPress.com Nyheter

On May 27, 2003, co-founders Matt Mullenweg and Mike Little announced that WordPress was available to the public. Their vision, as you can still read in their original post on WordPress.org, was to foster a means by which anyone could easily share and discuss their ideas with the world.
What started as a humble open-source blogging platform is now the driving force behind over one-third of the internet’s most popular websites, including The New York Times, Salesforce, and Disney. But the non-profit WordPress project continues to further its mission of democratizing publishing for the entire world. Just as Version 0.7 was available as a free download under the General Public License (GPL) 20 years ago, WordPress remains free today — at Version 6.2 and counting.

Automattic — the parent company of WordPress.com, Jetpack, Tumblr, and other web platforms and services — didn’t yet exist when Mike and Matt launched WordPress. But since its birth in 2005, the two organizations have worked hand in hand. Through the Five for the Future initiative, Automattic commits 5% of our company’s resources — including over 4,000 employee hours per week — to the open source WordPress project. In turn, we benefit from the amazing work they do in improving WordPress and ensuring the best possible experience for building and maintaining your website, no matter how small or large.
It’s a symbiotic relationship for which we have a deep appreciation. The WordPress community often uses a saying that we love: “A rising tide lifts all boats.” A healthy and thriving WordPress project benefits all of us.
So, to our friends in the WordPress open source community, we extend a heartfelt congratulations and thank you. Happy 20th anniversary! We can’t wait to see what the next two decades — and beyond — will bring.
Join 99,190,255 other subscribers
-
SEO5 dagar sedan
Event Link Building: En nybörjarguide
-
SÖKMOTORER5 dagar sedan
Google sökförslag för din sökning
-
SEO5 dagar sedan
Så här använder du Search Console-export av massdata
-
SÖKMOTORER5 dagar sedan
Google Search Algorithm Ranking Volatility 22 och 23 maj
-
SÖKMOTORER5 dagar sedan
Google Job Search Bug
-
SEO5 dagar sedan
Optimera nyhetswebbplatser med Google Search Console-rapporter
-
SOCIAL5 dagar sedan
YouTubes avgående YouTube-berättelser nästa månad
-
MARKNADSFÖRING7 dagar sedan
Hur Taco Bell förvandlade en varumärkesstrid till en marknadsföringskampanj