<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Privacy Breach Archives - Gizmochina</title>
	<atom:link href="https://www.gizmochina.com/tag/privacy-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.gizmochina.com/tag/privacy-breach/</link>
	<description>Latest Tech News, Product Reviews and Deals</description>
	<lastBuildDate>Fri, 09 Feb 2024 15:28:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.9</generator>
	<item>
		<title>Former Apple Engineer Sentenced for Stealing Self-Driving Car Secrets</title>
		<link>https://www.gizmochina.com/2024/02/09/apple-engineer-sentenced-self-driving/</link>
		
		<dc:creator><![CDATA[Anubhav]]></dc:creator>
		<pubDate>Fri, 09 Feb 2024 15:28:38 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Self-driving car]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=603838</guid>

					<description><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-300x169.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Apple logo" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo.jpg 800w" sizes="(max-width: 300px) 100vw, 300px" /><p>A former engineer at Apple, Xiaolang Zhang, finds himself on the wrong side of the law, having been handed a six-month prison sentence for his role in pilfering secrets from the tech giant&#8217;s vaults. This unfolds as Zhang admits to swiping details on the development of Apple&#8217;s self-driving vehicle project, an endeavour that people have [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2024/02/09/apple-engineer-sentenced-self-driving/">Former Apple Engineer Sentenced for Stealing Self-Driving Car Secrets</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="169" src="https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-300x169.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Apple logo" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-300x169.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-768x432.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-696x392.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo-747x420.jpg 747w, https://www.gizmochina.com/wp-content/uploads/2023/10/Apple-logo.jpg 800w" sizes="(max-width: 300px) 100vw, 300px" />
<p>A former engineer at <a href="http://gizmochina.com/category/apple">Apple</a>, Xiaolang Zhang, finds himself on the wrong side of the law, having been handed a six-month prison sentence for his role in pilfering secrets from the tech giant&#8217;s vaults. This unfolds as Zhang admits to swiping details on the development of Apple&#8217;s <a href="http://gizmochina.com/tag/self-driving">self-driving</a> vehicle project, an endeavour that people have been talking about for years.</p>



<h3>The fine includes a hefty sum of $146,984 as well</h3>



<p>Zhang&#8217;s journey from trusted employee to convicted felon began with his arrest at San Jose International Airport in 2018, moments before he could escape to <a href="http://gizmochina.com/tag/china">China</a>. Initially, he fought the charges, pleading not guilty. However, in a dramatic turn of events in 2022, Zhang confessed to the theft of trade secrets, leading to his current predicament. Beyond his prison term, Zhang faces a three-year leash of supervised release and a hefty restitution bill of $146,984.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="675" src="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-1024x675.png?x10805" alt="Apple" class="wp-image-570219" srcset="https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-1024x675.png 1024w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-300x198.png 300w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-768x506.png 768w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-696x459.png 696w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-1068x704.png 1068w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326-637x420.png 637w, https://www.gizmochina.com/wp-content/uploads/2023/09/Screenshot-2023-09-27-081326.png 1130w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>His tenure at Apple was marked by his involvement in Project Titan, Apple&#8217;s mysterious and much-discussed foray into autonomous vehicles. According to allegations, Zhang&#8217;s acts of espionage included transferring a detailed 25-page document with engineering blueprints to personal devices and pilfering hardware, illustrating a breach of trust as profound as it was audacious.</p>



<p>Following a paternity leave and a trip to China, Zhang resigned, revealing plans to join <a href="http://gizmochina.com/tag/xpeng">XPeng</a> Motors, a move that raised eyebrows given the company&#8217;s competing interests in autonomous driving. This revelation set off alarm bells, leading to an investigation that caught Zhang red-handed, engaging in activities that betrayed confidence.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2024/02/09/apple-wins-lawsuit-over-executive-compensation-for-tim-cook-and-others/">Apple wins lawsuit over executive compensation for Tim Cook and others.</a></li><li><a href="https://www.gizmochina.com/2024/02/09/apple-sells-the-most-smartphones-in-2023-with-seven-iphone-models-only-three-samsung-phones-in-the-list/">Apple Sells The Most Smartphones In 2023 With Seven iPhone Models, Only Three Samsung Phones In The List</a></li><li><a href="https://www.gizmochina.com/2024/01/09/get-redmi-k70-pro-for-discounted-price-of-499-at-giztop/">Get Redmi K70 Pro for discounted price of $499</a></li><li><a href="https://www.gizmochina.com/2024/01/10/oneplus-12-partners-with-pixelworks/">OnePlus partners with Pixelworks to Elevate Mobile Gaming Experience on the OnePlus 12</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="vivo X100 Pro Full Review: The Best Camera Phone?" width="696" height="392" src="https://www.youtube.com/embed/wFdgCKH1fHs?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.engadget.com/ex-apple-engineer-sentenced-to-six-months-in-prison-for-stealing-self-driving-car-tech-110537599.html?src=rss">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2024/02/09/apple-engineer-sentenced-self-driving/">Former Apple Engineer Sentenced for Stealing Self-Driving Car Secrets</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Hackers Turn Vigilantes &#8211; A Breach of WebDetetive Gives Poetic Justice</title>
		<link>https://www.gizmochina.com/2023/08/28/web-detetive-spyware-phones-compromised/</link>
		
		<dc:creator><![CDATA[Anubhav]]></dc:creator>
		<pubDate>Mon, 28 Aug 2023 01:31:55 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=561756</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Twitter" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w" sizes="(max-width: 300px) 100vw, 300px" /><p>Recent developments have brought to light the hacking of WebDetetive, a Portuguese-language spyware company that has been infecting Android phones in South America, primarily in Brazil. Interestingly, the company itself fell victim to hackers, who exploited multiple vulnerabilities to gain access to WebDetetive&#8217;s servers and user databases. At the time of the breach, over 76000 [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/08/28/web-detetive-spyware-phones-compromised/">Hackers Turn Vigilantes &#8211; A Breach of WebDetetive Gives Poetic Justice</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Twitter" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w" sizes="(max-width: 300px) 100vw, 300px" />
<p>Recent developments have brought to light the hacking of WebDetetive, a Portuguese-language spyware company that has been infecting Android phones in South America, primarily in <a href="http://gizmochina.com/tag/brazil">Brazil</a>. Interestingly, the company itself fell victim to hackers, who exploited multiple vulnerabilities to gain access to WebDetetive&#8217;s servers and user databases.</p>



<h3>At the time of the breach, over 76000 devices had been compromised.</h3>



<p>Notably, the unnamed hackers took the unprecedented step of not only downloading all the data but also severing the spyware&#8217;s network connection to victim devices. The group justified their actions saying, &#8220;Which we definitely did. Because we could. Because #fuckstalkerware.”</p>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" width="620" height="414" src="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg?x10805" alt="Twitter" class="wp-image-505620" srcset="https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF.jpg 620w, https://www.gizmochina.com/wp-content/uploads/2022/12/201912231455446402_Chinese-APT20-hacker-group-bypassing-2FA-in-latest-attacks_SECVPF-300x200.jpg 300w" sizes="(max-width: 620px) 100vw, 620px" /></figure></div>



<p>A data dump of 1.5 gigabytes, now in the hands of nonprofit DDoSecrets, revealed the extent of WebDetetive&#8217;s reach. At the time of the breach, 76,794 devices had been compromised, and the data included 74,336 unique customer email addresses.</p>



<p>Though it&#8217;s too early to determine the true identity of the hackers, or to confirm whether they&#8217;ve been successful in disconnecting the victim devices, their approach offers an intriguing counter-narrative. Normally cast as villains, these hackers instead appear as digital vigilantes, delivering poetic justice by using their skills to disable a network that invades people&#8217;s privacy.</p>



<p>However, the story takes a deeper twist. WebDetetive&#8217;s roots are linked to OwnSpy, another notorious spyware app developed in Spain. While the administrators of WebDetetive remain anonymous, the connection to OwnSpy suggests a broader ecosystem for these nefarious activities.</p>



<p><a href="http://gizmochina.com/tag/spyware">Spyware </a>companies like WebDetetive and OwnSpy exist in a murky legal environment, their coding often as questionable as their ethics. With this incident, questions around the “security” of these security companies are re-ignited. How can entities, notorious for their invasive capabilities, protect their own networks when they are this easily compromised?</p>



<p>While the hackers&#8217; actions raise legal and ethical questions, they also throw a spotlight on the fragility of spyware infrastructures. Ironically, the hackers&#8217; breach could serve as a wake-up call to users and potentially even law enforcement. But for now, it provides a touch of poetic justice in a domain often void of accountability.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/08/22/oneplus-8t-and-oneplus-10t-receiving-august-2023-security-patch-update/">OnePlus 8T and OnePlus 10T receiving August 2023 Security Patch update</a></li><li><a href="https://www.gizmochina.com/2023/08/22/oneplus-nord-2-update/">OnePlus Nord 2 receives August Android Security patch in India</a></li><li><a href="https://www.gizmochina.com/guides/best-10-8k-tvs-in-2023/">Best 10 8K TVs in 2023 – LG, Samsung, Hisense, &amp; More</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="We Just Visited the ECOVACS Global Event 2023: All About Household Robot" width="696" height="392" src="https://www.youtube.com/embed/RNR7pQWhqRY?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://techcrunch.com/2023/08/26/brazil-webdetetive-spyware-deleted/">Via</a>)</p>



<p></p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/08/28/web-detetive-spyware-phones-compromised/">Hackers Turn Vigilantes &#8211; A Breach of WebDetetive Gives Poetic Justice</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</title>
		<link>https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/</link>
		
		<dc:creator><![CDATA[Anubhav]]></dc:creator>
		<pubDate>Tue, 04 Jul 2023 03:59:29 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy Breach]]></category>
		<category><![CDATA[Wordpress]]></category>
		<guid isPermaLink="false">https://www.gizmochina.com/?p=548814</guid>

					<description><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Wordpress" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 300px) 100vw, 300px" /><p>In a shocking revelation, renowned security company Wordfence has recently uncovered a critical zero-day vulnerability in the widely used &#8220;user login system&#8221; plug-in, Ultimate Member, on the WordPress blogging platform. This vulnerability allows hackers to exploit their accounts and gain elevated administrative rights, effectively granting them full control over targeted websites. 200,000 websites have used [&#8230;]</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/">Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></description>
										<content:encoded><![CDATA[<img width="300" height="200" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg?x10805" class="webfeedsFeaturedVisual wp-post-image" alt="Wordpress" loading="lazy" style="display: block; margin: auto; margin-bottom: 5px;max-width: 100%;" link_thumbnail="" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 300px) 100vw, 300px" />
<p>In a shocking revelation, renowned security company Wordfence has recently uncovered a critical zero-day vulnerability in the widely used &#8220;user login system&#8221; plug-in, Ultimate Member, on the <a href="http://gizmochina.com/tag/wordpress">WordPress</a> blogging platform. This vulnerability allows hackers to exploit their accounts and gain elevated administrative rights, effectively granting them full control over targeted websites.</p>



<h3>200,000 websites have used the plugin until now</h3>



<p>The security flaw, identified as CVE-2023-3460, has been assigned a risk score of 9.8, indicating its severity. Through this vulnerability, cybercriminals can circumvent the plug-in&#8217;s built-in security measures, enabling them to manipulate the wp_capabilities configuration data of user accounts. By setting up their own accounts as administrators, hackers can assume complete control of compromised websites.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" width="1024" height="683" src="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg?x10805" alt="Wordpress" class="wp-image-548815" srcset="https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1024x683.jpg 1024w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-300x200.jpg 300w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-768x512.jpg 768w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1536x1024.jpg 1536w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-2048x1365.jpg 2048w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-696x464.jpg 696w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1068x712.jpg 1068w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-1920x1280.jpg 1920w, https://www.gizmochina.com/wp-content/uploads/2023/07/webfactory-ltd-MINfsRivuyg-unsplash-630x420.jpg 630w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>The plug-in&#8217;s developer has responded swiftly to address the issue. On June 26, they released Ultimate Member version 2.6.3, which provided partial mitigation against the vulnerability. Subsequently, on July 1, version 2.6.7 was released, offering a complete fix for the security flaw.</p>



<p>Disturbingly, it has come to light that over 200,000 WordPress websites have incorporated the Ultimate Member plug-in. Given the high number of installations and the potential delay in updating the plug-in due to inadequate information dissemination, these websites remain exceptionally vulnerable to exploitation by malicious actors.</p>



<p>Web administrators and website owners are strongly advised to take immediate action by updating their Ultimate Member plug-in to the latest version, 2.6.7, to safeguard their websites against potential attacks. Additionally, it is crucial to remain vigilant and monitor any suspicious activity or unauthorized access attempts.</p>



<p>Experts emphasize the significance of promptly addressing software vulnerabilities and staying up-to-date with the latest security patches. Regularly updating plug-ins and software is an essential practice that ensures website integrity and safeguards against emerging <a href="http://gizmochina.com/tag/cyber-threats">cyber threats</a>.</p>



<p><strong><span style="text-decoration: underline">RELATED:</span></strong></p>



<ul><li><a href="https://www.gizmochina.com/2023/04/07/twitter-api-shutdown-chaos-developers/">Twitter’s API Shutdown Causes Chaos for Developers</a></li><li><a href="https://www.gizmochina.com/2021/11/12/xiaomi-leads-in-phone-sales-during-this-years-11-11-shopping-festival-apple-in-second/">Xiaomi leads in phone sales during this year’s 11.11 shopping festival, Apple in second</a></li><li><a href="https://www.gizmochina.com/guides/best-ultra-budget-smartphones-of-2023/">Best Ultra Budget Smartphones of 2023</a></li></ul>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe loading="lazy" title="HHOLOVE O Sitter Review: The first and the Best companion AI robot for Cats" width="696" height="392" src="https://www.youtube.com/embed/WcMjsjKRai8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div></figure>



<p>(<a href="https://www.itworldcanada.com/article/cyber-security-today-july-3-2023-the-latest-ransomware-news-a-warning-to-wordpress-ultimate-member-administrators-and-more/542206">Via</a>)</p>
<p>The post <a rel="nofollow" href="https://www.gizmochina.com/2023/07/04/wordpress-plug-in-vulnerability-privacy-breach/">Zero-Day Vulnerability in Popular WordPress Plug-In Puts Thousands of Websites at Risk</a> appeared first on <a rel="nofollow" href="https://www.gizmochina.com">Gizmochina</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 43/53 objects using Redis
Page Caching using Disk: Enhanced 
Content Delivery Network Full Site Delivery via cloudflare
Database Caching 13/26 queries in 0.008 seconds using Redis
Fragment Caching 2/3 fragments using Redis

Served from: www.gizmochina.com @ 2026-04-16 19:14:21 by W3 Total Cache
-->