---
title: "WordPress Plugin Exploited, Proxyjacking: SSH Exploitation, macOS Targeted: ‘RustBucket’ Malware, Cybersecurity News [03 July 2023] | DuoCircle"
description: "Here are this week’s updates to update you on recent development in email security, among other cybersecurity news."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/"
---

Quick Answer

Four items. The Ultimate Member WordPress plugin (200,000+ installs) was actively exploited via a privilege-escalation flaw (CVE-2023-3460) that lets unauthenticated attackers create admin accounts; users were urged to update to 2.6.6\. Akamai documented a proxyjacking campaign that compromises SSH servers and rents their bandwidth to peer-to-peer proxy services like Peer2Profit and Honeygain. Elastic and Jamf identified a new variant of the Lazarus-linked RustBucket malware targeting macOS users in financial services. And researchers disclosed a Ghostscript flaw (CVE-2023-36664) that allows command execution via malicious PostScript or PDF documents in apps that ship Ghostscript, including LibreOffice and Inkscape.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=WordPress%20Plugin%20Exploited%2C%20Proxyjacking%3A%20SSH%20Exploitation%2C%20macOS%20Targeted%3A%20%E2%80%98RustBucket%E2%80%99%20Malware%2C%20Cybersecurity%20News%20%5B03%20July%202023%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F&title=WordPress%20Plugin%20Exploited%2C%20Proxyjacking%3A%20SSH%20Exploitation%2C%20macOS%20Targeted%3A%20%E2%80%98RustBucket%E2%80%99%20Malware%2C%20Cybersecurity%20News%20%5B03%20July%202023%5D "Share on Reddit") [ ](mailto:?subject=WordPress%20Plugin%20Exploited%2C%20Proxyjacking%3A%20SSH%20Exploitation%2C%20macOS%20Targeted%3A%20%E2%80%98RustBucket%E2%80%99%20Malware%2C%20Cybersecurity%20News%20%5B03%20July%202023%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/07/ant-phishing-2.jpg) 

Here are this week’s updates to update you on **recent development** in email security, among other [cybersecurity](/) news.

## Unpatched WordPress Plugin Flaw Exploited by Malicious Actors to Create Covert Admin Accounts

A critical unpatched vulnerability in the popular **Ultimate Member plugin** has put around [200,000 WordPress websites](https://thehackernews.com/2023/07/unpatched-wordpress-plugin-flaw-could.html) at risk of ongoing attacks.

Tracked as [CVE-2023-3460](https://nvd.nist.gov/vuln/detail/CVE-2023-3460) with a severity score of 9.8, the flaw affects all plugin versions, including the latest release (2.6.6) of June 29, 2023\. Exploiting the vulnerability allows threat actors to create new **user accounts with administrative privileges**, granting them complete control over the compromised sites.

_The flaw is related to inadequate **blocklist logic**, enabling attackers to modify ‘wp\_capabilities user meta value’ and elevate their access to the administrator level._

Although the plugin maintainers have issued partial fixes in versions 2.6.4, 2.6.5, and 2.6.6, WPScan has [found](https://blog.wpscan.com/hacking-campaign-actively-exploiting-ultimate-member-plugin/) methods to bypass these patches, indicating that the issue is **still actively exploitable**. Ultimate Member released version 2.6.7 on July 1, addressing the privilege escalation flaw and introducing [allow listing](https://web.archive.org/web/20231210083342/https://www.vmware.com/in/topics/glossary/content/allowlisting.html) for meta keys as a security enhancement.

_Users are advised to **turn off the plugin** and monitor administrator-level accounts for unauthorized additions until a comprehensive patch is available._

[![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/07/spf-record-tester-7519.jpg)](https://media.mailhop.org/duocircle/images/2023/07/spf-record-tester-7519.jpg)

## New Proxyjacking Campaign: Malicious Actors Exploit Vulnerable SSH Servers

A new **server hijacking** campaign has been discovered wherein [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) target vulnerable SSH servers secretly.

Researchers from Akamai have [identified](https://www.akamai.com/blog/security-research/proxyjacking-new-campaign-cybercriminal-side-hustle) an active campaign in which threat actors exploit SSH for remote access, employing **malicious scripts** to covertly enroll victim servers into a P2P (Peer-to-Peer) proxy network, such as Peer2Profit or Honeygain. Unlike cryptojacking, where compromised resources are exploited for cryptocurrency mining, proxy jacking allows the threat actors to utilize the **unused bandwidth** of victims to run various services as P2P nodes.

The anonymity provided by proxyware services can also enable malicious actors to obfuscate the **origin of their attacks** by routing traffic through intermediary nodes. The campaign, discovered on June 8, 2023, targets susceptible SSH servers, deploying an obfuscated [Bash script](https://ryanstutorials.net/bash-scripting-tutorial/bash-script.php) that retrieves dependencies from a compromised web server.

It is essential to implement robust security practices, such as using strong passwords, **regularly patching systems**, and maintaining detailed logging, to mitigate the risk of such attacks.

## Warning: macOS Users Targeted by New ‘RustBucket’ Malware Variant

Security researchers have uncovered [an advanced version](https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html) of the RustBucket malware targeting Apple macOS systems.

The updated variant, attributed to the North Korean threat actor BlueNoroff, showcases improved capabilities for persistence and **evading security software detection**. The [malware](/resources/malware-and-its-defense-mechanism), associated with the Lazarus Group, now employs a dynamic network infrastructure methodology for command and control, allowing it to establish a more persistent presence.

RustBucket was first identified in April 2023 as an **AppleScript-based** backdoor capable of retrieving a second-stage payload from a remote server. The second-stage malware is compiled in Swift and downloads the primary Rust-based binary from the C2 (Command and Control) server. This binary enables extensive data gathering and the execution of additional [Mach-O binaries](https://blog.efiens.com/post/luibo/osx/macho/) or shell scripts on compromised systems.

[![macOS Users](https://media.mailhop.org/duocircle/images/2023/07/anti-phishing.jpg)](https://media.mailhop.org/duocircle/images/2023/07/anti-phishing.jpg)

The attacks are primarily targeted toward **financial institutions** in Asia, Europe, and the U.S., necessitating these organizations to have efficient malware and [ransomware protection](/resources/locky-ransomware).

## Potential Security Risk: Ghostscript Bug Enables Execution of System Commands via Rogue Documents

Ghostscript, Adobe’s widely-used PostScript document composition system, has recently been found to have a bug, **CVE-2023-36664**.

The [flaw](https://nakedsecurity.sophos.com/2023/07/04/ghostscript-bug-could-allow-rogue-documents-to-run-system-commands/) allows malicious documents to create text and graphics and execute system commands through the **Ghostscript** rendering engine. The issue arises from Ghostscript’s handling of file names for output, as it can send output to a pipe instead of a regular file. By specifying specially-formatted filenames starting with strings like “%pipe%” or “|,” threat actors can launch commands on the victim’s system.

As the Ghostscript team released version 10.01.2 to address the bug, ensuring you have the **latest version** of Ghostscript to avoid any risk is essential. If you use a standalone package managed by your Linux distribution, Unix, or package manager like Homebrew on macOS, you must update it promptly to secure your system from such [vulnerabilities](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/).

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=WordPress%20Plugin%20Exploited%2C%20Proxyjacking%3A%20SSH%20Exploitation%2C%20macOS%20Targeted%3A%20%E2%80%98RustBucket%E2%80%99%20Malware%2C%20Cybersecurity%20News%20%5B03%20July%202023%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-27-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"WordPress Plugin Exploited, Proxyjacking: SSH Exploitation, macOS Targeted: ‘RustBucket’ Malware, Cybersecurity News [03 July 2023]","description":"Here are this week’s updates to update you on recent development in email security, among other cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/","datePublished":"2023-07-10T14:38:33.000Z","dateModified":"2025-05-21T12:09:22.000Z","dateCreated":"2023-07-10T14:38:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":666,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/ant-phishing-2.jpg","caption":"cybersecurity","width":999,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"WordPress Plugin Exploited, Proxyjacking: SSH Exploitation, macOS Targeted: ‘RustBucket’ Malware, Cybersecurity News [03 July 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"WordPress Plugin Exploited, Proxyjacking: SSH Exploitation, macOS Targeted: ‘RustBucket’ Malware, Cybersecurity News [03 July 2023]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"WordPress Plugin Exploited, Proxyjacking: SSH Exploitation, macOS Targeted: ‘RustBucket’ Malware, Cybersecurity News [03 July 2023]","description":"Here are this week’s updates to update you on recent development in email security, among other cybersecurity news.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/","datePublished":"2023-07-10T14:38:33.000Z","dateModified":"2025-05-21T12:09:22.000Z","dateCreated":"2023-07-10T14:38:33.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-27-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":666,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/07/ant-phishing-2.jpg","caption":"cybersecurity","width":999,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
