Fake SEO plugin backdoors WordPress installationsHelp Net Security·Aug 6, 13:01 UTC · Aug 6, 2019Malware42
Hackers Planted Secret Backdoor in Dozens of WordPress Plugins and ThemesThe Hacker News·Jan 22, 07:39 UTC · Jan 22, 2022MalwareCVE-2021-24867CVE-2022-021847
Nearly 2000 WordPress Websites Infected with a KeyloggerThe Hacker News·Jan 29, 12:40 UTC · Jan 29, 2018Malware30
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News·Jun 23, 03:40 UTC · Jun 23, 2026Malware in the wildCVE-2026-24858CVE-2025-59718CVE-2025-59719+1 CVEs60
Thousands of WP, Joomla and SquareSpace sites serving malicious updatesHelp Net Security·Jun 26, 21:20 UTC · Jun 26, 2018Malware30
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress SitesThe Hacker News·Jul 10, 11:30 UTC · Jul 10, 2026Malware in the wildCVE-2026-3844CVE-2021-29441CVE-2026-3300+10 CVEs60
Attackers behind Cloudflare_solutions Keylogger are back, 2000 WordPress sites already infectedSecurity Affairs·Jan 28, 07:23 UTC · Jan 28, 2018Malware30
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update LuresThe Hacker News·Jun 17, 08:52 UTC · Jun 17, 2026Malware42
Friday Squid Blogging: Squid Werewolf Hacking GroupSchneier on Security·Mar 28, 21:04 UTC · Mar 28, 2025Malware42
⚡ Weekly Recap: Chrome 0-Day, Data Wipers, Misused Tools and ZeroThe Hacker News·Jul 25, 08:27 UTC · Jul 25, 2026Malware in the wildCVE-2025-20286CVE-2025-49113CVE-2025-5419+8 CVEs60
ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool InstallersThe Hacker News·Mar 31, 11:33 UTC · Mar 31, 2026Malware42