Iceland 0-1 England: Sarina Wiegman's Lionesses hold nerve as Hannah Hampton produces late heroics once again to secure crucial win in World Cup qualifier
TARA ANSON-WALSH: England made sure not to waste the hard-earned advantage they claimed over Spain in their World Cup qualifying group earlier this week, backing it up with a crucial 1-0 win.
Steven Bartlett's 'biggest regret' on Dragons' Den is now worth £40million and on track to double its value in a year - despite BBC hopefuls asking for just £50k on show
The businessman, 33, has made a number of investments with budding entrepreneurs since joining the BBC programme in 2021. But there is one company that he wishes he got on board with.
United Airlines flight diverts and passengers escape on emergency slides amid 'bomb threat' after pilots 'hear beeping device'
The New York City-bound plane was rerouted to Pittsburgh International Airport on Saturday.
No need for expensive juices or harsh cleanses… dietitians reveal how to safely 'detox' your body with these simple changes
Your body already has a free, built-in detox system. What you really need isn't an expensive cleanse but simple, sustainable habits like better sleep, hydration, fiber-rich foods and less alcohol.
30 WordPress Plugins Turned Into Malware After Ownership Change
Wednesday BleepingComputer reported that more than 30 WordPress plugins "have been compromised with malicious code that allows unauthorized access to websites running them."
A malicious actor planted the backdoor code last year but only recently started pushing it to users via updates, generating spam pages and causing redirects, as per the instructions received from the command-and-control (C2) server. The compromise affects plugins with hundreds of thousands of active installations and was spotted by Austin Ginder, the founder of managed WordPress hosting provider Anchor Hosting, after receiving a tip about one add-on containing code that allowed third-party access.
Further investigation by Ginder revealed that a backdoor had been present in all plugins within the EssentialPlugin package since August 2025, after the project was acquired in a six-figure deal by a new owner.... "The injected code was sophisticated. It fetched spam links, redirects, and fake pages from a command-and-control server. It only showed the spam to Googlebot, making it invisible to site owners," explained Ginder.
"WordPress.org's v2.6.9.1 update neutralized the phone-home mechanism in the plugin," Ginder writes in a blog post. "But it did not touch wp-config.php. The SEO spam injection was still actively serving hidden content to Googlebot.
"And here is the wildest part. It resolved its C2 domain through an Ethereum smart contract, querying public blockchain RPC endpoints. Traditional domain takedowns would not work because the attacker could update the smart contract to point to a new domain at any time."
This has happened before. In 2017, a buyer using the alias "Daley Tias" purchased the Display Widgets plugin (200,000 installs) for $15,000 and injected payday loan spam. That buyer went on to compromise at least 9 plugins the same way.... The WordPress plugin marketplace has a trust problem... The Flippa listing for Essential Plugin was public. The buyer's background in SEO and gambling marketing was public. And yet the acquisition sailed through without any review from WordPress.org.
WordPress.org has no mechanism to flag or review plugin ownership transfers. There is no "change of control" notification to users. No additional code review triggered by a new committer. The Plugins Team responded quickly once the attack was discovered. But 8 months passed between the backdoor being planted and being caught.
Thanks to Slashdot reader axettone for sharing the news.
Read more of this story at Slashdot.
The fatal heart attack symptoms that are often dismissed as panic or anxiety... how to tell the difference before it's too late
Chest pain, racing heart and shortness of breath could be a harmless panic attack or a deadly heart attack. The two conditions mimic each other dangerously, but mistaking them could be deadly.
Taylor Swift's extraordinary measures to hide her private jet: Photos reveal $15 million makeover and secret new airborne identity to avoid detection
The Daily Mail has learned the singer has changed the plane's registration number in an effort to keep its movement hidden, following backlash over her heavy use of private flights.
Traitors winner Alan Carr turns Faithful as he looks to win village over to his £3million castle dream
As the ultimate Traitor, he famously plotted, schemed and connived his way to beating 18 of his fellow competitors to become celebrity king of the castle.
Cornwall locals who branded tourists 'ants' are now desperate for them to return - as restaurants, hotels and pubs are left on the brink by Labour's skyrocketing rates
Last summer saw locals expressing frustration over tourist crowds but the mood has changed, with footfall considered vital after the Government's 'quadruple hit' on the hospitality industry.
Fructose Isn't Just Sugar. It Acts More Like a Hormone
Slashdot reader smazsyr writes: A new review says we've had fructose wrong for decades. The nine authors, led by Richard Johnson at the University of Colorado Anschutz, argue that fructose "is not just another calorie." It is a signal. It tells the liver to make fat and brace for a famine that never comes. That made sense for a bear fattening up on autumn berries. It makes less sense for a person drinking soda in March.
The review reframes the WHO's sugar guideline, argues ScienceBlog.com, as "less a recommendation about calories and more a warning about a signalling molecule we have been dosing ourselves with, several times a day, for most of a century."
Read more of this story at Slashdot.
Trump warns Iran 'can't blackmail us' as crisis deepens in Strait of Hormuz
President Donald Trump said Iran cannot 'blackmail' the US after threatening to close the Strait of Hormuz again.
Cruz Beckham, 21, and his girlfriend Jackie Apostel, 30, put on a loved-up display during lavish Florida getaway
Cruz Beckham and his girlfriend Jackie Apostel put on a loved-up display during their lavish Florida getaway.
LIZ JONES: In which I suffer through a terrifying health emergency
In which there's an accident with a pony, a concussion and a dislocated shoulder. A team of four tried to pop the joint back into place for over two hours, to no avail.
‘High risk’ Essex man still wanted by police months after recall to prison
Police are still looking for him
Dua Lipa cosies up to her fiancé Callum Turner on safari in South Africa as couple pose for snaps with elephants and zebras
Sharing a series of photos to Instagram on Saturday, the singer, 30, posed with animals such as elephants and zebras on the tour.
All businesses face being targeted by hackers using AI tools doubling in power every four months, Technology Secretary warns
Liz Kendall said UK businesses of all sizes and in any sector were under threat from cyber attacks, not just government agencies or high-profile companies.
Little House on the Prairie star, 64, who played spoiled bully steps out after release of reboot trailer... see her now
Now actress Alison Arngrim was seen during a rare outing in Los Angeles on Wednesday.
Birthday girl Victoria Beckham blows out her candles and says she is 'so grateful' to her family after 'magical' day - despite silence from Brooklyn
Posh Spice took to her Instagram on Saturday to share a snap with her birthday cake following her celebrations.
Mia McKenna-Bruce says she finds it hard 'to be sexy' as she prepares to play Ringo Starr's wife in new Beatles biopic
Her career is in the ascendancy thanks to her high-profile roles playing an Agatha Christie sleuth, a murderer linked to the Royals and the wife of a Beatle.
20-Year-Old Enters Prison for Historic Breach, Ransoming of Massive Student Database
20-year-old Matthew Lane sent a text message to ABC News as his parents drove him to federal prison in Connecticut. "I'm just scared," he said, calling the whole situation "extremely sad."
Barely a year earlier, while still a teenager, he helped launch what's been described as the biggest cyberattack in U.S. education history — a data breach that concerned authorities so much, it prompted briefings with senior government officials inside the White House Situation Room. The breach pierced the education technology company PowerSchool — used by 80% of school districts in North America... [and operating in about 90 countries around the world]. With threats to expose social security numbers, dates of birth, family information, grades, and even confidential medical information, the breach cornered PowerSchool into paying millions of dollars in ransom.
"I think I need to go to prison for what I did," Lane told ABC News in an exclusive interview, speaking publicly for the first time about the headline-grabbing heist and his life as a cybercriminal. "It was disgusting, it was greedy, it was rooted in my own insecurities, it was wrong in every aspect," he said in the interview, two days before reporting to prison... At about 6:30 on a Tuesday morning last April, FBI agents started banging on the door of Lane's second-floor dorm room. "FBI! We have a search warrant," Lane recalled them shouting. They seized his devices and many of the luxury items he bought with "dirty" money, as he put it. He said he felt a "wave of relief.... I'm honestly thankful for the FBI," he said. "After they left, I was like, 'It's over ... I'm done with this'..."
A federal judge in Massachusetts sentenced him to four years in federal prison and ordered him to pay more than $14 million in restitution.
"In the wake of the breach, PowerSchool offered two years' worth of credit-monitoring and identity protection services to concerned customer," the article points out. But it also notes two other arrests in September of teenaged cybercriminals:
- A 15-year-old boy in Illinois who allegedly attacked Las Vegas casinos, reportedly costing MGM Resorts alone more than $100 million
- A British national who when he was 16 helped breach over 110 companies around the world and extort $115 million.
But ironically, Lane tells ABC News it all started on Roblox, where he'd met cheaters, password-stealers, and cybercriminals sharing photos of their stacks of money, creating a "sense of camaraderie"
Lane and others warn that online forums also attract criminal groups seeking to recruit potential hackers. "The bad guys are on all the platforms watching the kids playing," Hay said. "And when they see an elite-level performer, they go approach that kid, masquerading as another kid, and they go, 'Hey, you want to earn some [money]? ... Here are the tools, here are the techniques'...."
According to Lane, he spent his "ill-gotten gains" on designer clothes, diamond jewelry, DoorDash deliveries, Airbnb rentals for him and his friends, and drugs — "lots of drugs." He said he would numb ever-present feelings of guilt with drugs — from high-potency marijuana to acid. But it was hacking that gave him the strongest high. "It's indescribable the adrenaline you get when you do something like that," he said. "It's way more than driving 120 miles per hour. ... Incomparable to any drug at all, as well."
"On Monday, Roblox announced that, starting in June, it will offer age-checked accounts for younger users that limit what games they can play, and add 'more closely align content access, communication settings, and parental controls with a user's age.'"
Read more of this story at Slashdot.