The campaign has affected hundreds of WordPress websites. Attackers plant a rogue must-use plugin, named in the format ...
On August 15, 2026, I was gradually cleaning up the JavaScript for "Hajimete no Sangokushi". Just before that, I changed it so that reCAPTCHA is not loaded on regular articles that do not use Contact ...
A new wave of ClickFix social engineering attacks has been uncovered, adding to an already long list of campaigns using the widespread trick to compromise Windows computers with infostealers.
WordPress has released security updates for a vulnerability that could turn a failed login attempt into cross-site scripting and, under additional conditions, PHP code execution on the server.
A newly disclosed CVE-2026-64638, a pre-authentication cross-site scripting flaw in WordPress Core’s login screen that can be chained into full server-side remote code execution, earning a CVSS score ...
WordPress 7.1, scheduled for release on August 19, is scheduled to ship with a change that improves accessibility but will cause a breaking change to the admin page for a small number of users. While ...
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what ...
SocGholish, an operation that’s been delivering malware to users via fake software updates, has suffered a major blow: the international law enforcement coalition behind Operation Endgame has taken ...
Attackers have hijacked the code behind several popular WordPress plugins to plant hidden backdoors and rogue administrator accounts on as many as 1.2 million sites. The supply-chain attack, detailed ...
A supply-chain attack targeting the WordPress plugins OptinMonster, TrustPulse, and PushEngage exposed more than 1.2 million websites to potential compromise after attackers injected malicious ...
Sansec researchers discovered an active supply chain attack hitting WordPress sites running OptinMonster, TrustPulse, and PushEngage, three plugins operated by Awesome Motive, one of the largest ...
A newly discovered malware campaign targeting WordPress websites has raised serious concerns across the web security community. Attackers behind this campaign are using an unexpected method to ...