logo

Exposed Server Reveals 25,000 Compromised WordPress Websites

ID: 1f1077b8-1c97-5d55-88be-3e8ba6d468d7

STIX ID: report--1f1077b8-1c97-5d55-88be-3e8ba6d468d7

Feed Name: TechRepublic Security

Threat Score
70/100

Date Published: 2026-07-10

Date Updated: 2026-07-20

Author: Ken Underhill

...
...

An exposed WP-SHELLSTORM server revealed a large-scale, financially motivated campaign that automated exploitation of known WordPress and Joomla vulnerabilities to deploy obfuscated webshells (down.php), install persistence (SNOWLIGHT, VShell), steal enterprise cloud and database credentials, and resell site access; researchers found tooling, target lists (1.4M scanned, ~25k confirmed compromises per analysis, >17k webshells logged), and operational errors that exposed internal logs and infrastructure, and recommend patching, removing unused plugins, monitoring for IOCs, rotating credentials, and testing incident response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.