sucuri

Shadow Directories: A Unique Method to Hijack WordPress Permalinks

A new method of hijacking WordPress permalinks involves the creation of shadow directories. This technique allows attackers to inject spam content into search engine results without altering the visible content on the website or its database.

Malware Intercepts Googlebot via IP-Verified Conditional Logic

Some attackers are increasingly moving away from simple redirects in favor of more “selective” methods of payload delivery. This approach filters out regular human visitors, allowing attackers to serve malicious content to search engine crawlers.

WordPress Auto-Login Backdoor Disguised as JavaScript Data File

A WordPress backdoor has been discovered, disguised as a JavaScript data file, allowing attackers to automatically log into administrator accounts without credentials. This malware is hidden in a PHP file within the WordPress `wp-admin/js` directory.

Vulnerability & Patch Roundup — November 2025

This advisory provides a detailed overview of critical and high-risk vulnerabilities identified in various WordPress plugins and themes for November 2025. These vulnerabilities pose significant security risks.

Malvertising Campaign Hides in Plain Sight on WordPress Websites

The infection was identified when a customer noticed unauthorized JavaScript loading on their WordPress site. Investigation revealed that the same malicious script was active on at least 17 other websites.

Hidden WordPress Backdoors Creating Admin Accounts

A recent investigation uncovered two stealthy backdoors on a compromised WordPress site: a fake plugin named DebugMaster Pro and a script named wp-user.php. These files maintained persistent administrative access and exfiltrated credentials.

Malicious JavaScript Injects Fullscreen Iframe On a WordPress Website

A recent JavaScript-based malware campaign has been discovered targeting WordPress websites. The malware injects a fullscreen iframe from malicious domains, aiming to deceive users into executing a base64-encoded PowerShell command.

Uncovering a Stealthy WordPress Backdoor in mu-plugins

A stealthy backdoor has been discovered in WordPress installations, specifically targeting the mu-plugins directory. This malware leverages the must-use plugin mechanism to ensure automatic activation and persistence.

Stealthy PHP Malware Uses ZIP Archive to Redirect WordPress Visitors

A new stealthy PHP malware campaign has been discovered targeting WordPress websites. The malware leverages the `zip://` PHP wrapper to include obfuscated malicious code from a ZIP archive embedded in the WordPress core file `wp-settings.php`.

Stealthy WordPress Malware Drops Windows Trojan via PHP Backdoor

A stealthy malware campaign has been discovered targeting WordPress websites to deliver a Windows-based RAT through a PHP backdoor. The infection chain involves a malicious ZIP archive containing the trojan executable.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags