Just saw this on ZDNet. Websense® ThreatSeeker® Intelligence Cloud has detected that the official website of Popular Science has been compromised and is serving malicious code (iFrame).
The code is of the redirect type and will send the user to other websites which will drop malicious files (RIG Exploit Kit) on the victim’s computer. RIG is an executable. If the user doesn’t have any of the checked AVs installed, then the exploit kit proceeds to evaluate the installed plug-ins and their versions, in particular Flash, Silverlight, and Java. If a vulnerable plug-in is found, the appropriate exploit is launched.
Just so you know, PopSci has been notified…but if you’ve been there recently, best you head over to herdProtect and let it scan your system. If the results come back positive on several AVs you’d best get busy changing passwords and checking your credit card/banking, etc. accounts
Source:
http://www.zdnet.com/zero-day-weekly-currentc-hacked-white-house-breached-apt28-exposed-verizon-shamed-7000035269/