
🇮🇹 Sintesi in Italiano
L’ecosistema WordPress è in preda a un allarme silenzioso. Nonostante gli sviluppatori abbiano corretto due falle critiche la settimana scorsa, diversi attori malintenzionati hanno trovato il modo di exploitarle sul campo. Aziende di cybersecurity come Patchstack, Hexastrike e WatchTowr hanno lanciato l’allerta: i criminali informatici stanno letteralmente prendendo il controllo di siti web che ancora girano su versioni vulnerabili del popolare software. Si parla di una piaga digitale che mette a rischio milioni di contenuti online! La situazione è un po’ nebulosa, ma si sa che le versioni colpevoli rientrano in fasce specifiche (come 6.9.0-6.9.4 e 7.0.0-7.0.1). Secondo i dati ufficiali di WordPress, potremmo parlare di centinaia di milioni di siti con questo ‘problema’, ma un esperto ha calcolato che forse circa 90 milioni sono realmente a rischio oggi. L’attenzione è tutta su questi tipi di falle: ne è stata riscoperta una in particolare (chiamata WP2Shell) e, combinandola con l’altra bug corretta, gli hacker possono ottenere un pieno controllo remoto dei siti compromessi. Per fortuna, il settore sta reagendo: si parla di aggiornamenti automatici spinti da WordPress stesso e anche servizi esterni come Cloudflare che stanno bloccando molti tentativi di attacco. Insomma, è una corsa contro il tempo per chi gestisce questi contenuti online: l’aggiornamento non è un optional, ma sopravvivenza digitale!
🇬🇧 Summary in English
The digital world is sending out a flashing ‘Warning!’ sign about WordPress. Despite the developers having rushed to patch two critical security flaws last week, bad actors have found ways to exploit them in the wild. Cybersecurity outfits like Patchstack, Hexastrike, and WatchTowr have sounded the alarm: hackers are actively taking over websites still running susceptible versions of the popular blogging platform. It’s a digital plague that puts millions of sites at risk! While the exact number is hard to pin down, we know the culprit version ranges (think 6.9.0-6.9.4 and 7.0.0-7.0.1). The sheer scale is staggering; officially, there are hundreds of millions of vulnerable sites out there. However, estimates suggest that perhaps around 90 million sites face current threats. The key vulnerability was highlighted by a bug discovered in particular (dubbed WP2Shell), which, when paired with the other patched flaw, grants hackers full remote control over compromised sites. Thankfully, defensive measures are kicking in: WordPress itself is pushing forced updates, and services like Cloudflare are blocking many attack attempts. For site owners, the takeaway is crystal clear: updating isn’t a suggestion—it’s an immediate necessity for digital survival.
Leggi l’articolo originale su TechCrunch →
Fonte: TechCrunch | Argomento: Cybersecurity
#tecnologia #innovazione #technews