Skip to content
tag — wordpress

grep -rl "wordpress" ./articles

#wordpress

7 articles

The WordPress backdoor lives in eight places at once, and each one rebuilds the others

2026-10-02Security

Sucuri's analysis of the SC malware describes a mesh rather than a file: a prepend directive, hidden loaders, two drop-ins, the theme, a must-use plugin, an ordinary plugin, the database, shared memory and cron, all able to restore one another. Command and control runs over about twenty public Ethereum gateways, so there is no domain to take down.

440,000 blocked attempts is a WAF metric, not a compromise count

2026-09-08Security

Wordfence blocked more than 250,000 attempts against Super Forms and more than 190,000 against Elementor Pro. Both flaws are unauthenticated file upload, both are patched, and the Super Forms campaign has been running since 14 July. What nobody has published is how many sites actually fell.

The payloads sit on a blockchain testnet, which is free

2026-09-08Security

Netskope found over 5,400 compromised WordPress and PrestaShop sites pulling their next stage from smart contracts on the BNB Smart Chain testnet. EtherHiding is not new. Putting it on the testnet is, because the testnet costs nothing, behaves like the real chain, and has no abuse desk to write to.