Threat research, walkthroughs, and security guides from the RedSecLabs team.
Product Update | Version 2.5.0 The WordPress dashboard should not be the only place you discover that an administrator has…
Series Context Article 1 covers the incident-response case: multiple unauthorised administrators, wp2shell exposure analysis, backdoor checks and recovery. This article…
Case-study Boundary The affected pharmaceutical organisation is anonymised. The investigation confirmed multiple unauthorised WordPress administrator accounts. The circumstances were consistent…
Two of the most common entry points for WordPress compromises aren’t exotic zero-days or sophisticated attacks. They’re plugins that stopped…
Next-generation plugin uses LLM-assisted reasoning to detect sophisticated backdoors and hidden malware that traditional security tools miss Guardian Gaze, a…
Most WordPress sites don’t get hacked because someone targeted them personally. They get compromised because security was ignored until it…