HomeinetJoomla 3.4.6 upgrade immediately

Joomla 3.4.6 upgrade immediately

The Joomla security team has managed to fix a highly critical zero-day bug, which appears to have already been used to compromise websites using the platform.Joomla security

A while ago the Joomla security team released version 3.4.6, along with security patches for older versions of the CMS, even if some of them are no longer officially supported.

Upgrade Now!

The reason behind this critical code update is a zero-day bug that allows attackers to insert code into the Joomla database and execute it.

Security experts at Sucuri claim that attacks that exploit this technique have already been observed.

The first attacks began on December 12, but today, the wave of attacks was even greater according to the security company.

Therefore, due to the criticality of the issue, website owners using the platform should immediately upgrade to version 3.4.6 or apply the security patches offered by the Joomla security team, for all versions of the CMS, starting from 1.5.x.

Additionally, webmasters should look in their logs for requests originating from the following IP addresses: 146.0.72.83, 74.3.170.33 or 194.28.174.106, as most of today's attacks originated there.

The malicious code contains the strings “JDatabaseDriverMysqli” or “O:”

The latest version of Joomla is available on Github.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS