Creepy Crawlers: Hunting Those Who Hunt For WordPress Plugins
ID: 24c5c32f-7d78-58a7-88a2-9f4c4b79e89e
STIX ID: report--24c5c32f-7d78-58a7-88a2-9f4c4b79e89e
Feed Name: GreyNoise Labs
GreyNoise observed ~40K unique WordPress plugin enumeration events over 92 days, revealing coordinated and persistent scanning from multiple ASNs (notably UCLOUD HK, Akamai/Linode) including 91 single-plugin specialists focused on the post-smtp plugin, a large Sri Lanka Telecom-driven spike scanning 334 plugins in two days, and weekend-biased automated scanning; the report ties scanning activity to published CVEs for targeted plugins (e.g., post-smtp account-takeover CVE) and recommends tagging, JA4-based alerting, weekend monitoring, and patching high-risk plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
