Threat research, walkthroughs, and security guides from the RedSecLabs team.
Security teams rarely lose sleep over the server that is already in the vulnerability scanner. The awkward one is the…
A backdoor is built to survive the obvious cleanup. This guide explains what local WordPress scanners, remote analysis, host-level tools…
How poisoned dependencies, compromised build pipelines and trusted plugin updates reach WordPress sites, what the 2026 incidents teach us, and…
Product Update | Version 2.5.0 The WordPress dashboard should not be the only place you discover that an administrator has…
During a Guardian Gaze SOC integration, the RedSecLabs (RSL) team needed to bring WordPress security telemetry into an existing Wazuh…
Series Context Article 1 covers the incident-response case: multiple unauthorised administrators, wp2shell exposure analysis, backdoor checks and recovery. This article…
Case-study Boundary The affected pharmaceutical organisation is anonymised. The investigation confirmed multiple unauthorised WordPress administrator accounts. The circumstances were consistent…
Every WordPress security plugin before 2024 worked the same way: maintain a database of known malware signatures, compare your files…
Wordfence is the leading free WordPress security plugin, but its in-process scanner has limitations that modern malware can exploit. Here's…
Think your WordPress site has been hacked? Learn how to confirm the infection, clean every compromised file and database entry,…