Mmastodon TechnologyCybersecurity first seen 15 h ago, last 15 h ago, peak #11
Sucuri details self-rebuilding WordPress backdoor tied to wpForo attacks
Original: 🤖 Sucuri dissects a WordPress backdoor ("SC") that rebuilds itself after cleanup: persistence via files, DB entries, and
Security firm Sucuri has analyzed a WordPress backdoor, dubbed "SC", that restores itself after administrators clean infected sites. The malware persists through injected files, database entries, and shared memory, making removal difficult. Sucuri links it to exploit attempts targeting the wpForo forum plugin, with fewer than 20 incidents observed since July 3. WordPress site owners are being urged to check for signs of infection.
Why now: The malware's ability to rebuild itself after cleanup alarms site administrators and highlights ongoing WordPress plugin exploitation.
SucuriWordPressSC backdoorwpForo
Evidence
- 🤖 Sucuri dissects a WordPress backdoor ("SC") that rebuilds itself after cleanup: persistence via files, DB entries, and shared memory. Tied to wpForo exploit attempts (fewer than 20 seen since July 3). 🔗 https:// thehackernews.com/2026/10/word… · cloud@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/699559