
Critical Security Alerts: WordFence Scanning, Popper Blocker Spyware, and MikroTik RouterOS Vulnerability
The SANS Internet Storm Center detected honeypot requests for wordfence-waf.php, a file associated with WordFence's web application firewall for WordPress. Attackers are likely scanning for this file to identify sites protected by WordFence or to find sites that previously used the service but no longer have active protection. The Popper Blocker browser extension, downloaded by over 2 million users with a 4.8 star rating, has been identified as spyware that exfiltrates every URL visited and captures chats with top AI tools, violating Google's policies. The malware evades detection by initially appearing benign, then loading additional scripts in a custom scripting language that enable spyware functionality. CISA published an advisory for CVE-2024-84411, a critical vulnerability in MikroTik RouterOS that allows unauthenticated remote code execution as root through an HTTP request triggering an integer underflow. The vulnerability appears to have been silently patched in RouterOS version 7.24 released in August, though no corresponding advisory exists on MikroTik's website.