Anatomy of a Persistent WordPress Infection: Five Layers Deep

When a customer reports “something is filling up disk space,” the instinct is to look for a runaway log file or a misconfigured backup job. Most of the time, that’s exactly what it is. This time, it wasn’t, and what we found underneath is a good case study in how modern WordPress compromises are built…

How We Caught a Supply Chain Attack in a Single Log Line

On September 14, 2026, attackers compromised the Admin Menu Editor Pro update server and pushed malware to thousands of WordPress sites. Here is how we found it, traced it, and what you need to do right now. September 15, 2026  ·  We Watch Your Website Security Team  ·  Supply Chain Action Required If you or…

The Bill Comes Due: What AI-Accelerated Vulnerability Discovery Is Actually Costing Us

Moving faster is more expensive On September 8, 2026, Microsoft shipped the largest Patch Tuesday in its history: 974 CVEs, more than any single release the company has ever issued, blowing past the previous record of 570 CVEs set just two months earlier in July. Microsoft has openly attributed part of the surge to MDASH,…

The Backdoor That Healed Itself: Anatomy of a Self-Reinstalling WordPress Infection

The Backdoor That Healed Itself: Anatomy of a Self-Reinstalling WordPress Infection

Most WordPress cleanups are boring, and that’s how you want them. You find the bad file, you delete the bad file, you patch the hole it came through, you’re done. This one was not boring. It’s the kind of infection that makes you doubt your own eyes — you delete a file, refresh, and it’s…

Seven copies, four tables, one file: the WordPress infection that rebuilt itself from its own database

A new client contacted us regarding a site that continually reinfected within minutes of every cleanup. The reason was not a file anyone had missed. The malware had turned the database into a mirror of itself, and every copy knew how to rebuild every other copy. The site had been through a partial remediation months…

Most WordPress Plugins on GitHub Never Reach the Official Directory. Here’s Why That’s a Security Problem.

What we saw We monitor traffic across the sites we watch, and we track IP addresses with a history of malicious behavior. A pattern kept surfacing in the logs. One flagged address would visit a site briefly, touching the kind of paths that reveal which plugins are installed. Reconnaissance, essentially, building an inventory of what…

The Real Attack Vector Responsible for 60% of Hacked WordPress Sites in 2023

Introduction  WordPress Security is full of myths that have no basis in reality or data. A particularly pervasive one is the unsubstantiated claim that “95% of WordPress hacks are due to outdated plugins or themes.“ If that’s the case, then during times of no current zero-day exploits, or the lack of major vulnerable plugins and…